7.5

CVE-2026-14780

PaperCut NG/MF: Remote Code Execution via Scripting Subsystem

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.  

A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPaperCut
≫
Produkt PaperCut NG/MF
Default Statusunaffected
Version 0
Version < 25.0.12
Status affected
Version 26.0.0
Version < 26.0.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.213
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
eb41dac7-0af8-4f84-9f6d-0272772514f4 7.5 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://www.papercut.com/kb/Main/security-bulletin-sep-2026/