CVE-2023-27350General(papercut / papercut_mf)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch papercut papercut_mf systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-05-12. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • papercut_mf
  • papercut_ng

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 10 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • General: 3 classified signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-29); latest day: 1
  • 11 total mentions across 10 days

Affected systems

Vendors
Products
papercut_mfpapercut_ng

Deep dive

Activity timeline11 mentions / 10d
01122Mentions · 2026-01-27: 1Mentions · 2026-02-03: 1Mentions · 2026-03-10: 1Mentions · 2026-03-29: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Mentions · 2026-07-22: 1Mentions · 2026-08-29: 2Mentions · 2026-08-31: 1Mentions · 2026-09-05: 1PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-07-22: 1Exploit Tool / Code · 2026-09-05: 1Active Exploitation · 2026-08-29: 2Active Exploitation · 2026-09-05: 1Patch / Workaround · 2026-08-29: 2Technical Details · 2026-01-27: 1Technical Details · 2026-02-03: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-29: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 1Technical Details · 2026-07-22: 1Technical Details · 2026-08-29: 101-2702-0303-1003-2904-1904-2107-2208-2908-3109-05
Signal classification5 categories
General
327.3%
Disclosure
327.3%
Active Exploitation
327.3%
PoC
19.1%
Exploit
19.1%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-01-271
PoC1
2026-02-031
General1
2026-03-101
Disclosure1
2026-03-291
Disclosure1
2026-04-191
General1
2026-04-211
Disclosure1
2026-07-221
Exploit1
2026-08-292
Active Exploitation2
2026-08-311
General1
2026-09-051
Active Exploitation1
Full discourse11 posts
  • 0xdf@0xdf_
    General

    Bamboo from @hackthebox_eu and @vulnlab_eu features Squid proxy enumeration, CVE-2023-27350 authentication bypass to RCE in PaperCut NG, and binary hijacking of a root-executed script for privilege escalation. https://0xdf.gitlab.io/2026/02/03/htb-bamboo.html

    Post summary

    The writeup highlights the CVE‑2023‑27350 authentication bypass that allows RCE in PaperCut NG and includes privilege escalation details, but does not provide PoC, exploit code, patches, or evidence of active exploitation.

    112066213.3K
    25.9K followersView on X
  • PCMedicalist@PCMedicalist
    Active Exploitation

    PCMedicalist Signal · Aug 29 CVE-2023-27350--PaperCut NG/MF Critical Zero-Day Exploited in the Wild: patch PaperCut NG/MF Critical Zero-Day Exploited in the Wild and verify the fix held. Full brief 👇 #CyberSecurity #ZeroDay #InfoSec PCMedicalist · https://pcmedicalist.com/intel https://t.co/fkdsk39qEE

    Post summary

    The tweet announces that CVE‑2023‑27350, a critical zero‑day in PaperCut NG/MF, has been actively exploited in the wild and urges installing the vendor’s patch.

    0001084
    151 followersView on X
  • RST Cloud@rst_cloud
    Exploit

    #threatreport #HighCompleteness Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries | 20-07-2026 Source: https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve Key details below ↓ 💀Threats: Adaptixc2_tool, Supershell, Nginx_rift_vuln, Clickfix_technique, Impacket_tool, Goby_tool, 🎯Victims: Government, Universities, Healthcare, Financial services, Academic, Private sector 🏭Industry: Government, Financial, Education, Healthcare 🌐Geo: Italy, Brazil, France, Vietnam, Singapore, Australia, Chinese, South korea, United states, Indonesia, United kingdom, Ireland, New zealand 🔓CVEs: CVE-2023-27350 \[[Vulners](https://vulners.com/cve/CVE-2023-27350)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - papercut papercut_mf (<20.1.7, <21.2.11, <22.0.9) - papercut papercut_ng (<20.1.7, <21.2.11, <22.0.9) CVE-2026-4480 \[[Vulners](https://vulners.com/cve/CVE-2026-4480)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - redhat openshift_container_platform (4.0) - samba (<4.2.1) - redhat enterprise_linux (7.0, 8.0, 9.0, 10.0) CVE-2026-26980 \[[Vulners](https://vulners.com/cve/CVE-2026-26980)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True Soft: - ghost (<6.19.1) CVE-2024-3273 \[[Vulners](https://vulners.com/cve/CVE-2024-3273)] - CVSS V3.1: *7.3*, - Vulners: Exploitation: True Soft: - dlink dns-320l_firmware (1.01.0702.2013, 1.03.0904.2013, 1.11) CVE-2026-20253 \[[Vulners](https://vulners.com/cve/CVE-2026-20253)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - splunk (<10.0.7, <10.2.4) CVE-2026-42945 \[[Vulners](https://vulners.com/cve/CVE-2026-42945)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - f5 dos (le4.7.0, 4.8.0) - f5 nginx_gateway_fabric (le1.6.2, le2.5.1) - f5 nginx_ingress_controller (le3.7.2, le4.0.1, le5.4.1) - f5 nginx_instance_manager (le2.21.1) ... CVE-2017-10271 \[[Vulners](https://vulners.com/cve/CVE-2017-10271)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - oracle weblogic_server (10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0) 📚TTPs: ⚔️Tactics: 2 🛠️Technics: 0 🤖LLM extracted TTPs:` T1190, T1583.001, T1583.003, T1588.002, T1588.005, T1595.002 🧨IOCs: - IP: 2 - File: 4 - Hash: 1 - Domain: 4 💽Software: NGINX, PaperCut, WebLogic, mysql, GoDaddy 🔢Algorithms: sha256 🔠Functions: system ⚙️Win Services: print-spooler 📜Programming Languages: golang, javascript, python #threatreport: In mid-2026, significant vulnerabilities were discovered in NGINX and Ghost CMS, leading to potential cyber exploits targeting governmental and financial institutions across eleven countries. The two primary vulnerabilities included NGINX Rift (CVE-2026-42945), a heap overflow in the NGINX rewrite module, and a blind SQL injection in the Ghost CMS Content API (CVE-2026-26980). Public exploit code for both was released shortly after their discovery, prompting attackers to develop and deploy creative methods to leverage these vulnerabilities. An exposed directory on an active Singapore-based VPS revealed the operational details of a cyber threat actor leveraging these vulnerabilities. The directory, housing a variety of exploits, contained tools for multiple attack techniques, including reverse shell setup and out-of-band (OOB) DNS callbacks to confirm malware execution. The target sectors indicated a strategic approach, primarily focusing on high-value entities like federal governments, educational institutions, healthcare providers, and financial services. The NGINX Rift vulnerability was used in targeted attempts to exploit live infrastructure. An exploitation script (http://poc.py) relied on specific memory addresses and settings that necessitated a low-security environment, indicating a phase of development rather than direct application on active targets. The actor’s exploration revealed little success during these attempts. On the other hand, the Ghost CMS exploit allowed the attacker to interact with the database without authentication, making it easier to extract sensitive information. By running a public exploit script, the actor conducted checks to identify vulnerable hosts and subsequently attempted data extraction. The implications of CVE-2026-26980 extend beyond this singular event, as it had been previously associated with larger campaigns aimed at mass exploitation. Additional exploits in the toolkit included those targeting well-known vulnerabilities in systems such as PaperCut, Oracle WebLogic, and D-Link NAS devices. The operator's use of OOB verification methods, like directing DNS queries to uniquely generated subdomains, offered a means to validate successful exploit execution despite potential network response filtering. Command and control infrastructure included the presence of widely recognized exploitation frameworks like AdaptixC2 and Supershell, although these tools were not directly linked to any specific intrusion captured in the analysis. The operational artifacts uncovered indicated a systematic approach to database exploitation, along with diligent targeting across nations including Brazil, France, South Korea, and others, primarily within sectors that handle sensitive data. While specific compromise outcomes were not confirmed in the gathered evidence, this activity exemplified a competent cyber threat actor exploiting newly discovered vulnerabilities and old, effective techniques with awareness and precision. The existence of these exploits and their deliberate targeting underscores the need for heightened vigilance and proactive defense measures within the cybersecurity landscape to mitigate similar attacks.

    Post summary

    The report details the release and use of functional exploit scripts for CVE-2026-42945 and CVE-2026-26980, providing technical specifics but no evidence of confirmed in‑the‑wild exploitation or available patches.

    00010302
    721 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers chained CVE-2023-27350 and CVE-2023-27351 to compromise PaperCut servers at educational institutions, then deployed registry harvesting tools to extract Windows credentials. Campaign demonstrates how third-party application compromises enable credential theft across academic networks. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/papercut-cve-2026-81578-82078-credential-theft-education-sector-2026

    Post summary

    The text reports real-world attacks where CVE-2023-27350 and CVE-2023-27351 were exploited against PaperCut servers in educational institutions, resulting in credential theft via registry harvesting tools.

    0000074
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    General

    TRC analysis shows attackers chaining two PaperCut vulnerabilities (CVE-2023-27350, CVE-2023-27351) to gain initial access then pivot across network segments. Runtime segmentation limits blast radius when print management systems become pivot points for lateral movement. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisa-kev-papercut-vulnerabilities-cve-2026-81578-82078-august-2026

    Post summary

    The report outlines how attackers exploit and chain PaperCut CVEs to achieve network pivoting, but provides no evidence of active exploitation, PoC, or patch information.

    0000063
    2.0K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness PaperCut NG/MF Critical Zero-Day Exploited in the Wild | 28-08-2026 Source: https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild Key details below ↓ 🎯Victims: Enterprise organizations, Educational institutions 🏭Industry: Education 🔓CVEs: CVE-2023-27350 \[[Vulners](https://vulners.com/cve/CVE-2023-27350)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - papercut papercut_mf (<20.1.7, <21.2.11, <22.0.9) - papercut papercut_ng (<20.1.7, <21.2.11, <22.0.9) 🤖LLM extracted TTPs:` T1059.007, T1190, T1546 🧨IOCs: - File: 3 - IP: 0 - Domain: 0 - Url: 0 - Hash: 0 - Email: 0 - BrowserExtension: 0 💽Software: PaperCut, Apache Tapestry 📜Programming Languages: javascript #threatreport: PaperCut Software reported active exploitation of a critical, currently unassigned zero-day affecting PaperCut NG and PaperCut MF. All versions are considered potentially impacted. The vulnerability affects the PaperCut Application Server and is especially dangerous when its web interfaces are accessible from the public internet. PaperCut released emergency patches for versions 25 and 26 on August 28, 2026, but has not publicly provided a CVE identifier, CVSS score, or complete vulnerability classification. The flaw is described as an authentication bypass that allows unauthenticated attackers to invoke privileged PaperCut components. By abusing Apache Tapestry’s direct request format, an attacker can cause a public Error or Exception page to be displayed while executing administrative components associated with ConfigEditor or UserList. This bypass can expose functionality intended to configure external database lookups. Attackers can configure a malicious JDBC connection and SQL statement, then trigger the lookup through a forged UserList request. The reported exploitation chain abuses PaperCut’s bundled Apache Derby driver, using a Derby `CALL` statement and the `foreignViews` feature to access an attacker-controlled H2 JDBC URL. An H2 inline `INIT` statement can create a JavaScript-backed database trigger. Because PaperCut includes the Nashorn JavaScript engine, the trigger can launch an operating-system process, resulting in remote code execution. Other command-execution mechanisms may also be possible.

    Post summary

    PaperCut NG/MF has been actively exploited in the wild via an authentication bypass that leads to remote code execution, prompting emergency patches for versions 25 and 26 released on August 28, 2026.

    00000197
    786 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PaperCut NG, Authentication Bypass, #CVE-2023-27350 (High) https://dailycve.com/papercut-ng-authentication-bypass-cve-2023-27350-high/

    Post summary

    The message announces a high‑severity authentication bypass vulnerability (CVE-2023-27350) in PaperCut NG, without mentioning PoC, exploit code, patches, or active exploitation.

    0000051
    183 followersView on X
  • 無重力トレーニング@acupunc28094787
    General

    I just completed PaperCut: CVE-2023-27350 room on TryHackMe! Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://tryhackme.com/room/papercut?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65869e2abbbd1398b6caad7d #tryhackme via @tryhackme

    Post summary

    The tweet references the PaperCut CVE‑2023‑27350 and a TryHackMe room, noting an authorization bypass that allows remote code execution, but provides no specific PoC, exploit code, or mitigation details.

    0000054
    95 followersView on X
  • Sun4lower@LittleSun4lower
    Disclosure

    I just completed PaperCut: CVE-2023-27350 room on TryHackMe! Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://tryhackme.com/room/papercut?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #consistency

    Post summary

    The tweet announces the CVE-2023-27350 authorization bypass in PaperCut Print Management software, explains it leads to remote code execution, and points to a TryHackMe room for more details, without providing a PoC, exploit, or patch.

    0000085
    5 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    Disclosure

    I just completed PaperCut: CVE-2023-27350 room on TryHackMe! Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://tryhackme.com/room/papercut?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet announces a TryHackMe training room that explores PaperCut’s CVE-2023-27350, describing it as an authorization bypass that permits remote code execution, without mentioning exploits, patches, or debunking claims.

    0000043
  • Jayesh Verma@JayeshV88153533
    PoC

    I just completed PaperCut: CVE-2023-27350 room on TryHackMe. Authorisation bypass (CVE-2023-27350) in PaperCut Print Management software leading to remote code execution. https://tryhackme.com/room/papercut?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=684d724b80fe1af75347f3e4 #tryhackme via @tryhackme

    Post summary

    The tweet promotes a TryHackMe room demonstrating an authorization bypass in PaperCut that results in RCE, providing a PoC of the vulnerability.

    0000083
    16 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppapercutpapercut_mf---
Apppapercutpapercut_ng---

Explore more