A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.papercut.com/kb/Main/security-bulletin-sep-2026/ |
|
Thu, 24 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Papercut
Papercut papercut Mf |
|
| Vendors & Products |
Papercut
Papercut papercut Mf |
Thu, 24 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox. A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system. | |
| Title | PaperCut NG/MF: Remote Code Execution via Scripting Subsystem | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PaperCut
Published:
Updated: 2026-09-24T13:21:40.570Z
Reserved: 2026-07-05T05:53:18.115Z
Link: CVE-2026-14780
Updated: 2026-09-24T13:21:37.479Z
Status : Received
Published: 2026-09-24T06:17:00.567
Modified: 2026-09-24T14:17:11.570
Link: CVE-2026-14780
No data.
OpenCVE Enrichment
Updated: 2026-09-24T09:00:12Z