CVE-2026-11744

LOWCVSS 3.8 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a specially crafted NFC card or emulator could exploit this flaw to execute arbitrary code within the context of the application's user interface. This could result in unauthorized actions or information disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Full discourse1 post
  • CyberSignal | Cybersecurity & AI News@XQOPTRX

    🚨 SECURITY BULLETIN — PaperCut has disclosed four vulnerabilities affecting PaperCut NG/MF and its Ricoh embedded application. CyberSignal Priority: 🟠 HIGH The vulnerabilities are: CVE-2026-14780 Authenticated RCE through the scripting subsystem. CVE-2026-82077 Authenticated administrator RCE through Scan2Fax. CVE-2026-87739 Unauthenticated authorization bypass allowing unauthorized report generation and potential information disclosure. CVE-2026-11744 JavaScript injection affecting the PaperCut Hive embedded application for Ricoh devices and requiring physical access. 🛡️ Fixes PaperCut NG/MF: → 26.0.5 or later → 25.0.13 or later on the 25.x branch PaperCut Hive Ricoh Embedded App: → 2.3.0 or later ⚠️ Important caveat PaperCut says it currently has no evidence that these vulnerabilities have been exploited. CyberSignal Insight: Not every RCE equals unauthenticated compromise — both PaperCut RCE vulnerabilities require existing administrator access, which significantly changes the threat model. Sources: PaperCut · CERT-FR

    0101036
    226 followersView on X

Explore more