CVE-2026-14780
A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox. A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.
- Published Sep 24, 2026
- CVSS 7.5 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- Multiple vulnerabilities in Papercut CERT-FR ·