CRITICAL

CVE-2026-82078

Papercut Papercut Mf 2026-08-28 CVSS v3.1
CVSS
9.1
KEV

Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Weakness (CWE)

CWE-470

EPSS Score

3.57%
Probability of exploitation in next 30 days
88.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE