CVE-2026-6645Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-23: 1Technical Details · 2026-06-23: 106-23
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Autumn Good@autumn_good_35
    Disclosure

    『CVE-2026-6645 (Insecure Search Path): insecure search path vulnerability in the PaperCut Print Deploy Client for Windows that could allow a local attacker to execute arbitrary code.』 PaperCut NG/MF Security Bulletin (June 2026) https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-june-2026/

    Post summary

    PaperCut released a security bulletin announcing a new local execution vulnerability (CVE‑2026‑6645) caused by an insecure search path in its Print Deploy Client for Windows.

    01000460
    6.9K followersView on X

Explore more