CVE-2026-82077: PaperCut Ng/mf

High severity, CVSS 7.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

Affected products

  • PaperCut PaperCut Ng/mf: before 25.0.13 (fixed in 25.0.13); from 26.0.0, before 26.0.5 (fixed in 26.0.5)

Published 2026-09-24. Last modified 2026-09-25.