CVSS v3
—
Unknown
EPSS Score
0.5 %
exploit probability
CISA KEV
Yes
known exploited
Exploitation
—
SSVC status
Description
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
CISA Known Exploited Vulnerability
- Date Added
- 2026-08-31
- Patch Due Date
- 2026-09-14
- Ransomware Use
- Unknown
Technical details
- Published
- 2026-08-28
- Last Modified
- 2026-08-29
Frequently asked questions
What is CVE-2026-82078?
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Is CVE-2026-82078 actively exploited?
Yes. CVE-2026-82078 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 2026-09-14.
What is the CVSS score for CVE-2026-82078?
A CVSS score has not been assigned to CVE-2026-82078 yet.
Is CVE-2026-82078 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2026 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).
- CVE-2026-24061KEV
- CVE-2026-27174MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
- CVE-2026-60004KEV
- CVE-2026-1281KEV
- CVE-2026-24423KEVSmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
- CVE-2026-1731KEVRemote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
- CVE-2026-23760KEVSmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
- CVE-2026-22200osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read