CVE-2024-1221: PaperCut MF

Low severity, CVSS 3.1. EPSS: 0.5% chance of exploitation in the next 30 days.

This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affects Linux and macOS PaperCut NG/MF servers.

Affected products

  • PaperCut PaperCut MF: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
  • PaperCut PaperCut NG: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)

Published 2024-03-14. Last modified 2026-06-17.