Unsafe database driver class loading enables exploitation chain to code execution on PaperCut NG/MF servers (CVE-2026-82078)
PaperCut released an updated Emergency Patch (Release 2) on August 28 while confirming customer incidents from active exploitation, and internet-facing servers left unpatched and unrestricted remain open to compromise via a pre-auth exploitation chain.
PaperCut MF and NG instantiate database driver classes from configurable driver names without validating against an allowlist, letting an attacker who can manipulate configuration parameters execute arbitrary Java bytecode on the classpath as the PaperCut server process. Huntress reports the flaw is being chained (alongside CVE-2026-81578) into pre-authentication remote code execution against exposed servers.
Affected: PaperCut MF < 24.1.10, < 25.0.13, < 26.0.5; PaperCut NG < 24.1.10, < 25.0.13, < 26.0.5
How to Test
Check your Application Server version against the fixed releases (24.1.10 / 25.0.13 / 26.0.5) and determine whether its web interface is reachable from the public internet; PaperCut says to act now even if no suspicious activity has been observed, and to watch the bulletin for indicators of compromise as the investigation continues.
How to Patch
Upgrade to PaperCut MF/NG 24.1.10, 25.0.13, or 26.0.5, or apply the vendor's Emergency Patch Release 2 (recommended even if the original emergency patch was already applied), verifying installers against the published SHA256 checksums; immediately restrict the PaperCut server's web interfaces to trusted internal IP addresses using firewall rules or network access controls.