PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct CVE-2026-81578

Severity
EPSS Score
EPSS Percentile
Vulnerability description
Not available
Risk description
Not available
Recommendation
Not available
Codename
Not available
Detectable with
Network Scanner
Scan engine
Nuclei
Cisa Kev
Cybersecurity Infrastructure Security Agency (CISA) Yes
Exploitable with Sniper
No
CVE Published
Aug 28, 2026
Detection added at
Software Type
Not available
Vendor
papercut
Product
papercut_ng,papercut_mf

Detect this vulnerability now!

Check your clients' targets (or your own) for this vulnerability and thousands more! Get proof for validation with our ethical hacking toolkit.