SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82078

CRITICAL · CVSS 9.1 EPSS 1.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut MF and NG allows attackers to execute arbitrary Java bytecode by manipulating system configuration parameters, as the application fails to validate driver names against an allowlist. This critical flaw, with a CVSS score of 9.4, poses a significant risk to organizations using these products, particularly those with exposed configurations. Organizations utilizing PaperCut MF or NG should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82078
Severity
CRITICAL
CVSS
9.1
EPSS
1.69%
Java

Original NVD Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)