OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-82077

HIGH · CVSS 7.3 EPSS 0.74%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows authenticated administrators to exploit path traversal issues, enabling them to execute arbitrary commands on the underlying host through manipulated fax provider settings. This poses a significant risk as it can lead to unauthorized access and control over the system. Organizations using these PaperCut products should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-82077
Severity
HIGH
CVSS
7.3
EPSS
0.74%

Original NVD Description

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.