{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-81578",
  "revision": 1,
  "title": "PaperCut MF/NG — Unauthenticated Access to Admin Configuration",
  "summary": "The web management interface of PaperCut print servers runs some administrative actions before it finishes checking who asked, so an attacker with only network access can change system configuration without logging in. It can be chained with CVE-2026-82078.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.0329,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-08-31",
    "prerequisites": "Network access to the PaperCut MF or NG web management interface; no credentials needed"
  },
  "remediation": {
    "patch_available": true
  },
  "kill_chain": "initial_access",
  "recommended_action": "Update PaperCut MF and NG per the vendor security bulletin, keep the web admin interface off the public internet, and review system configuration for changes you did not make.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-81578",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-81578",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-81578",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81578",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/rapid7/metasploit-framework/pull/21842"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578"
    }
  ],
  "published_at": "2026-08-28T16:18:29.600Z",
  "issued_at": "2026-09-21T07:05:11.841Z",
  "tags": [
    "papercut",
    "print-management",
    "access-control",
    "missing-authentication"
  ]
}
