CVE-2024-1222: PaperCut MF

Critical severity, CVSS 9.8. EPSS: 64% chance of exploitation in the next 30 days.

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

Affected products

  • PaperCut PaperCut MF: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)
  • PaperCut PaperCut NG: before 20.1.10 (fixed in 20.1.10); from 21.0.0, before 21.2.14 (fixed in 21.2.14); from 22.0.0, before 22.1.5 (fixed in 22.1.5); from 23.0.1, before 23.0.7 (fixed in 23.0.7)

Published 2024-03-14. Last modified 2026-06-17.