Multiple vulnerabilities were identified in PaperCut. A remote attacker could exploit these vulnerabilities to trigger security restriction bypass and remote code execution on the targeted system.
Note:
CVE-2026-82078 and CVE-2026-81578 are being exploited in the wild. For CVE-2026-82078, under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks; For CVE-2026-81578, if an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers.