CVE-2026-87739: PaperCut Ng/mf
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.
Affected products
- PaperCut PaperCut Ng/mf: before 25.0.13 (fixed in 25.0.13); from 26.0.0, before 26.0.5 (fixed in 26.0.5)
Published 2026-09-24. Last modified 2026-09-24.