CVE-2024-1222: PaperCut MF
Critical severity, CVSS 9.8. EPSS: 64% chance of exploitation in the next 30 days.
This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.
Affected products
- PaperCut PaperCut MF: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
- PaperCut PaperCut NG: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
Published 2024-03-14. Last modified 2026-06-17.