CVE-2026-14780

Summary

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.

A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.

Affected Software

VendorProductVersion RangeStatus
PaperCutPaperCut NG/MF0 < 25.0.12affected
PaperCutPaperCut NG/MF26.0.0 < 26.0.2affected

Weaknesses

  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References