CVE-2026-14780: PaperCut Ng/mf
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox. A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.
Affected products
- PaperCut PaperCut Ng/mf: before 25.0.12 (fixed in 25.0.12); from 26.0.0, before 26.0.2 (fixed in 26.0.2)
Published 2026-09-24. Last modified 2026-09-25.