An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.papercut.com/kb/Main/security-bulletin-sep-2026/ |
|
History
Thu, 24 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information. | |
| Title | PaperCut MF/NG: User permissions are not evaluated on report generation | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PaperCut
Published:
Updated: 2026-09-24T06:46:54.879Z
Reserved: 2026-09-09T04:24:33.190Z
Link: CVE-2026-87739
No data.
Status : Received
Published: 2026-09-24T07:16:34.780
Modified: 2026-09-24T07:16:34.780
Link: CVE-2026-87739
No data.
OpenCVE Enrichment
Updated: 2026-09-24T08:30:17Z
Weaknesses