CVE-2026-82077

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

  • Published Sep 24, 2026
  • CVSS 7.3 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-82077 at the National Vulnerability Database