CVE-2026-82078
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 1.69%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-470
- Published
- 2026-08-28
- Last modified
- 2026-09-01
Affected products
- PaperCut PaperCut MF/NG
Weakness type
Related vulnerabilities
- CVE-2026-41871 — Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-58400 — GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter
- CVE-2026-19032 — jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
- CVE-2026-55559 — Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)
- CVE-2026-54614 — DebugKit: MailPreview contains unsafe reflection
- CVE-2026-79784 — Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration
- CVE-2026-68508 — Hydra: hydra.utils.instantiate with untrusted config can lead to code execution