← CYBERNETICSINTERN.COMCYBERNETIC INTERN
IncidentTechnical analysis

Changing a setting was the same as running code

PaperCut NG and MF are under active exploitation. Two flaws chain into pre-auth code execution, and the one scored lower is the one that mattered.

Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.

A compromised PaperCut server writes the evidence into its own log, and it looks like a database problem:

ERROR No suitable driver found for jdbc:no:x

A print management server complaining that it cannot find a database driver is not obviously an intrusion. It is one. That string is on PaperCut’s published indicator list, alongside four others, and it is the visible end of a chain that begins with an unauthenticated HTTP request and finishes with commands running as SYSTEM [1].

The part worth stopping on is how the two flaws in that chain were scored. One was rated CRITICAL. The other, the one without which none of it works, was rated HIGH, because on its own all it does is change a setting.

What happened

At 9:42 a.m. AEST on Thursday, August 27, 2026, PaperCut received a report from an education sector customer saying a server had been compromised. The first working theory was an n-day, some known flaw on an unpatched box. In the company’s own account of the response, the evidence “didn’t fit” [2]. By midday it was a P0 and the assumption had changed to a zero-day under active exploitation. A second organisation reported the same pattern at 5:05 p.m. that afternoon, and the forensics from the two together let PaperCut reconstruct the chain [2].

Huntress dates one of the two intrusions it saw to August 26, which reads like a contradiction until you convert the clocks. AEST is UTC+10, so PaperCut’s 9:42 a.m. on August 27 is 11:42 p.m. on August 26 in UTC. The two accounts describe the same night [2][6].

Both CVEs were published on August 28. CISA added them to the Known Exploited Vulnerabilities catalog on August 31, 2026 with a remediation date of September 14, 2026, and records ransomware campaign use as Unknown for both [5].

Then the patching got interesting. PaperCut shipped an emergency patch, then Emergency Patch Release 2 on the evening of August 28 with hardening developed alongside Huntress and watchTowr, then Emergency Patch Release 3 at 6:22 p.m. AEST on September 1. Release 3 is cumulative and supersedes both earlier ones. It also fixes two regressions the earlier patches introduced: broken SAML login flows, and lost support for legacy Microsoft SQL Server drivers in external card lookup [1].

Three emergency patches in five days, and PaperCut’s advisory now reports a second wave of attacks against servers that are still unpatched and still reachable, with more sophisticated post-compromise behaviour than the first days [1].

Why this matters

For a large share of the installed base there is no patch to apply. Huntress reports that 47 percent of the roughly 2,500 PaperCut installations it tracks are running v23 or older, for which no fix exists [6]. PaperCut’s guidance for those versions is to upgrade [1], and upgrading a print platform across a school district is not a Tuesday afternoon job. A meaningful population is sitting on network isolation as its only control.

Print servers are trusted in ways nobody documents. PaperCut NG and MF are deployed heavily across education, healthcare and government [7]. The Application Server holds directory integration, sits centrally, and on Windows runs as SYSTEM. Nobody has ever asked to see the print server’s threat model.

This has happened before, and it ended in ransomware. CVE-2023-27350 in the same product was broadly exploited by multiple groups including ransomware operators [7]. CISA records ransomware use for the 2026 pair as Unknown [5], so that is precedent rather than observation. It is the precedent I would plan against.

Technical breakdown

Two flaws, neither sufficient alone.

CVE-2026-81578 is the way in. Huntress describes the mechanism: a crafted request can name one page to be rendered for the response while a different page owns the component actually being executed, and PaperCut’s authorisation check could trust the first and miss the permissions required by the second [6]. NVD’s description puts the same thing in terms of ordering, saying unauthenticated requests targeting administrative functions can trigger backend actions before access validation completes [3]. The result either way is that an unauthenticated attacker changes server configuration.

CVE-2026-82078 is what that configuration is worth. The database connection utility instantiates driver classes from a configurable driver name, without checking the name against an allowlist of approved drivers [4]. Name a class that exists on the application classpath and the server loads it and runs it, in the security context of the PaperCut server process.

Read those together and the shape is clear. The first bug lets an unauthenticated caller write configuration. The second makes one configuration field a name for code. NVD scores CVE-2026-82078 with PR:H, privileges required high, which is accurate, because ordinarily only an administrator edits that field [4]. The first bug removes the requirement.

Huntress reproduced the full pre-authentication chain against a stock PaperCut NG 25.0.11.75758 and confirmed it by watching charmap.exe execute as SYSTEM underneath the pc-app.exe application server process [6]. That is a deliberately harmless demonstration binary, and its appearance under a print server process is exactly as wrong as it sounds.

Two numbers for the same flaw

Here is the part I went and checked rather than accepting, and it did not reconcile the way I expected.

Both NVD records carry two scores, one assigned by NVD under CVSS 3.1 and one supplied by the vendor as CNA under CVSS 4.0:

CVE NVD, CVSS 3.1 Vendor, CVSS 4.0
CVE-2026-81578, authentication bypass 9.8 CRITICAL [3] 8.8 HIGH [3]
CVE-2026-82078, unsafe reflection 9.1 CRITICAL [4] 9.4 CRITICAL [4]

The ranking inverts. Under 3.1 the authentication bypass is the worse of the two. Under 4.0 it is the milder one, and it changes severity band on the way. A team that filters on CRITICAL in a tool showing CVSS 4.0 sees one of these two vulnerabilities. A team filtering the same way in a tool showing 3.1 sees both.

The 4.0 vector explains itself honestly: confidentiality impact low, integrity impact high, availability low, and no impact on any subsequent system. For an attacker who can only edit configuration, that is a fair assessment. Configuration is data. Except that here one configuration value was a Java class name, so it was not data, and the subsequent system impact was total.

A smaller mismatch sits alongside it: NVD classifies CVE-2026-81578 as CWE-305 [3], while PaperCut’s bulletin and CISA’s KEV entry both use CWE-306, missing authentication for critical function [1][5]. Nothing turns on it unless you pivot on weakness class, in which case these land in different buckets depending on where you look.

EPSS tells a similar story about fresh vulnerabilities. Checked against FIRST on September 2, 2026, both CVEs sit mid-distribution at the 53rd and 58th percentiles [8], while being KEV-listed with confirmed exploitation. EPSS forecasts the next 30 days from observed activity, and five days into a zero-day there is almost nothing for it to observe.

The chain

ATTACK CHAIN
  1. ReconnaissanceThe actor locates PaperCut Application Servers whose web interface answers from the public internet
    BREAK THE CHAIN HERE
    Restrict the Application Server web interface to trusted internal addresses using firewall rules or network ACLs. PaperCut names this as the immediate action, ahead of patching, for any internet-facing server. Alert on inbound connections to the admin interface from outside your management ranges.
  2. Authorisation bypassA crafted request names one page for rendering and a different component for execution, and the permission check reads the first
  3. Configuration writeWith the check bypassed, an unauthenticated request modifies server configuration that normally requires an administrator
    BREAK THE CHAIN HERE
    Emergency Patch Release 3 for v24, v25 and v26. It is cumulative and supersedes Releases 1 and 2, so earlier patches do not need installing first. On v23 and earlier no patch exists and isolation is the only control.
  4. Driver name poisonedThe database connector accepts a driver class name from configuration and instantiates it with no allowlist check
  5. Class loadingJava bytecode reachable on the application classpath is loaded and executed inside the PaperCut server process
    BREAK THE CHAIN HERE
    Confirm security.card-number-lookup.enabled in server/security.properties. The default is N, which disables external card lookup. Alert on the server.log strings "No suitable driver found for jdbc:no:x" and "Database error looking up cardID: VALUES CAST".
  6. Execution as SYSTEMCommands run in the security context of the application server, which on Windows is SYSTEM
  7. DiscoveryAccount, host, session and domain controller enumeration runs within the first six minutes
    BREAK THE CHAIN HERE
    Alert on pc-app.exe spawning cmd.exe or powershell.exe. Huntress published Sigma logic for this parent and child relationship, and PaperCut lists the same behaviour among its indicators.
  8. Remote access installedA commercial remote monitoring agent is downloaded and registered as an auto-starting service running as LocalSystem
  9. Anti-forensicsStaged files are deleted and server.log is truncated or removed, so the absence of indicators clears nothing

What the actor did after landing

PaperCut published the observed command sequence as elapsed time from the first command. Discovery starts immediately: account and OS at zero, process list at one minute, domain controller enumeration at four, logged-on users and the contents of the users directory at six. At sixteen minutes a remote access binary is pulled down, at nineteen it runs, and at twenty-one a Windows service named Remote Access Service appears, running a SimpleHelp agent as LocalSystem. AnyDesk follows at twenty-seven [1]. Huntress saw an Atera agent in its cases instead [6].

Different tools, same intent. None of it is malware in the sense an antivirus vendor cares about. It is commercial remote support software installed as a service, which is why the useful detection is the parent process rather than the binary.

The payload cleans up after itself. The Java class file recovered by Huntress decodes data written under the server’s content directory, executes it, then deletes what it wrote [6]. That is why PaperCut says plainly that absent indicators do not rule out compromise, and why a missing or truncated server.log belongs on the indicator list rather than in the noise [1].

One detail makes the log strings readable rather than magic. Java class files begin with the four bytes 0xCAFEBABE. PaperCut’s indicator Database error looking up cardID: VALUES CAST(X'cafebabe [1] is therefore a card lookup being handed a compiled Java class where a card number should be. The log describes the whole attack, in the vocabulary of a database error.

What defenders should do Monday morning

Immediate, within 24 hours.

Determine whether your Application Server web interface answers from the internet. If it does, restrict it to trusted internal addresses before you think about patching [1]. This control works on every version, including the ones with no fix.

Apply Emergency Patch Release 3 on v24, v25 and v26. It is cumulative, so earlier releases do not need installing first, and it repairs the SAML and legacy SQL Server driver regressions [1]. Patch Site Servers and secondary print servers too. Mobility Print, Print Deploy and the user clients are unaffected [1].

Search server.log across every PaperCut host for the advisory’s indicator strings, and treat a missing or truncated log as a finding rather than a gap [1].

Near term, this week.

On v23 and earlier, accept that isolation is the only control and put a date on the upgrade [1][6].

Hunt the post-compromise tooling: a Windows service named Remote Access Service running SimpleService.exe from the JWrapper path, plus AnyDesk, Atera or any remote support agent nobody can account for [1][6]. Write the detection if you do not have it, because pc-app.exe as a parent of cmd.exe or powershell.exe should never be routine [6].

Check security.card-number-lookup.enabled in the config file rather than the console. The default is off, and PaperCut warns that with the key unset the admin interface can still show the feature as configured while the server ignores it [1]. A UI that disagrees with the config file is worth discovering before an incident.

If you suspect compromise, rebuild. PaperCut’s own guidance is to secure current backups, wipe and rebuild the Application Server, and restore from a backup taken before the suspicious activity [1]. Cleaning in place is not on the list.

Structural, this quarter.

Find every place in your estate where a configuration value selects a class, a driver, a plugin, a template path or a callback, and reclassify write access to those fields as equivalent to code execution. That is the transferable lesson and it has nothing to do with printing.

Record which CVSS version each of your tools reports. You now have a worked example where that choice changes which vulnerabilities clear a CRITICAL filter.

Get print infrastructure off the internet edge and keep it there.

Checklist

  • PaperCut Application Server web interface confirmed unreachable from untrusted networks
  • Emergency Patch Release 3 applied on v24, v25 and v26
  • Site Servers and secondary print servers patched, not just the primary
  • v23 and earlier hosts identified, isolated, and given an upgrade date
  • server.log searched for the advisory’s indicator strings on every PaperCut host
  • Missing or truncated server.log files investigated rather than ignored
  • Hosts checked for a Remote Access Service Windows service and for unaccounted AnyDesk or Atera installs
  • Detection in place for pc-app.exe spawning a command shell
  • security.card-number-lookup.enabled verified in the config file, not the admin UI
  • Rebuild path agreed in advance for any host you cannot clear

Configuration is code, and we keep scoring it as data

The interesting failure here is not the class loader. Unsafe reflection is a known weakness with a CWE number and a well-understood fix, and PaperCut has shipped one.

The interesting failure is that an authentication bypass whose only power was to edit configuration got scored as the lesser of the two flaws, by a vector recording no impact on any subsequent system. That was reasonable in isolation and wrong in reality, because on this product one configuration field held the name of a class the server would obligingly load. Config was code. The scoring model had no way to say so.

Every product you run has fields like this. Driver names, plugin paths, template locations, webhook targets, serialisation allowlists, log appender definitions. Settings in the UI, execution primitives in the runtime, and the distance between those two readings is one missing authorisation check. If you take one thing from this incident, make it the inventory question rather than the patch.

A word for PaperCut, which I did not expect to write. They shipped three imperfect patches in five days, said publicly that two of them broke SAML and legacy driver support, published the hour they first heard, and credited the outside researchers who found more. Patch iteration reads as incompetence if you count releases instead of reading them, and vendors know it, which is why so many wait and ship one quiet fix three weeks later. Given that choice, I will take the noise.

FREQUENTLY ASKED

We run PaperCut but it is not on the internet. Are we safe?
Safer, and not finished. Network exposure is the control PaperCut names first, and restricting the Application Server web interface to trusted internal addresses removes the internet-facing attack path. It does not remove the flaw. Anyone already inside your network, including a compromised workstation, still reaches an unpatched server. Treat isolation as the thing that buys you time to patch, not as the patch.
We are on PaperCut v23. What are our options?
There is no patch for v23 or earlier and PaperCut has said the path for those versions is to upgrade rather than wait. Until you do, network isolation is the only control you have. This is not a small group: Huntress reports that 47 percent of the roughly 2,500 installations it tracks are on v23 or older.
Why is the authentication bypass rated HIGH when the chain gives full code execution?
Because it was scored on what it does alone. The CVSS 4.0 vector on the vendor's assessment records low confidentiality impact, high integrity impact and no impact on subsequent systems, which is a defensible reading of an attacker who can only modify configuration. On this product a configuration value named a Java class, so modifying configuration was equivalent to running code. NVD's own CVSS 3.1 assessment of the same flaw is 9.8 CRITICAL.
Our scanner shows a low EPSS score for these. Does that mean low risk?
No, and this is a good illustration of what EPSS is for. As of September 2, 2026 both CVEs sit near the middle of the distribution, around the 53rd and 58th percentiles. EPSS forecasts exploitation over the next 30 days from observed telemetry, and a five-day-old zero-day has almost no telemetry behind it yet. KEV membership is the signal that applies here, and both are listed.
How would I know if we were already hit?
Start with server.log, then accept that its absence proves nothing. PaperCut publishes several exact log strings tied to the exploitation attempt, and the payload observed in the wild deletes the files it writes. A missing or truncated server.log is itself an indicator. After the logs, look for a Windows service named Remote Access Service running SimpleService.exe, and for AnyDesk, Atera or other remote access tooling nobody remembers installing.

REFERENCES

  1. [1]URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)PaperCut Software · Published August 27, 2026 · Accessed September 2, 2026PRIMARY
  2. [2]Behind the scenes: what happened after 9:42 a.m. on the 27th August 2026PaperCut Software · Published September 1, 2026 · Accessed September 2, 2026PRIMARY
  3. [3]CVE-2026-81578 DetailNational Vulnerability Database (NIST) · Published August 28, 2026 · Accessed September 2, 2026PRIMARY
  4. [4]CVE-2026-82078 DetailNational Vulnerability Database (NIST) · Published August 28, 2026 · Accessed September 2, 2026PRIMARY
  5. [5]Known Exploited Vulnerabilities Catalog (JSON feed), catalog version 2026.09.02Cybersecurity and Infrastructure Security Agency (CISA) · Published September 2, 2026 · Accessed September 2, 2026PRIMARY
  6. [6]PaperCut Zero-Day: Active Exploitation and Pre-Auth RCEHuntress · Published August 27, 2026 · Accessed September 2, 2026VENDOR RESEARCH
  7. [7]PaperCut NG/MF Critical Zero-Day Exploited in the WildRapid7 · Published August 28, 2026 · Accessed September 2, 2026VENDOR RESEARCH
  8. [8]EPSS scores for CVE-2026-81578 and CVE-2026-82078, model date 2026-09-02FIRST (Forum of Incident Response and Security Teams) · Published September 2, 2026 · Accessed September 2, 2026PRIMARY

BEFORE YOU GO

Was this useful?

Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.

SEND FEEDBACK ↗

The newsletter

Follow along

Notes between posts, and whatever I'm breaking in the lab.

LINKEDIN ↗