Skip to content
Brief Security & Trust ·

PaperCut fixes were bypassed several times, watchTowr says

Only two of the flaws were used in attacks; the rest were found by watchTowr while it studied PaperCut's patches.

In brief
  • Only CVE-2026-81578 and CVE-2026-82078 were exploited in attacks. watchTowr found the later bypasses and CVE-2026-82077 itself.
  • watchTowr says PaperCut has no single permission check across pages. Each fix closed one route, so patching alone may not be enough.

Security firm watchTowr said on 9 October that PaperCut's print software had a chain of flaws letting an outsider run commands without logging in. PaperCut warned on 27 August 2026 that attackers were using a flaw, but it had no patch yet. watchTowr said only two flaws were used in attacks: CVE-2026-81578, a login bypass, and CVE-2026-82078, which runs commands after login. watchTowr found the later patch bypasses and a new command flaw, CVE-2026-82077, while studying PaperCut's fixes.

watchTowr did not report attacks using those later findings. It did not say how many organisations were hit or who was behind it. It said the web framework, Apache Tapestry 3, lets one request name several pages, and PaperCut checks permissions only on the first. With no one permission check across all pages, watchTowr said, tracking every page is hard. Builds 26.0.4-PO 76530 and 26.0.5 fix its newest two findings. One finding, WT-2026-0141, has no CVE number.

In watchTowr's account, each patch closed one route and another was found. Patching alone may not be enough. Budget owners can ask whether the admin interface is open to the internet, who owns the print server, and how fast the vendor fixes problems. watchTowr says schools, hospitals, governments and law firms use PaperCut.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: watchTowr.