CVE-2026-82077

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.

CVSS
7.3
EPSS
0.007 (53.1th percentile)
CISA KEV
Not listed
Exploitation
none
Public exploits
None seen
State
PUBLISHED

Coverage

What we observed

No signals recorded