First published · Last updated
CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF contains a missing authentication for critical function vulnerability that allows an unauthenticated remote attacker to modify certain system configurations and can be chained with CVE-2026-82078. The advisory requires applying vendor mitigations and following CISA BOD 26-04 guidance or discontinuing use if mitigations are unavailable.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 8/10
- Geographic reach
- 4/10
- Global importance
- 3/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
Unauthenticated remote modification of system configurations poses a direct security risk and requires stakeholders to apply mandated mitigations.

