PaperCut NG and MF ConfigEditor Authentication Bypass Vulnerability Remote Code Execution Exploit

This module exploits CVE-2026-81578, an improper access control vulnerability combined with CVE-2026-82078, an unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut NG and MF to deploy an OSCI agent. The module will use the vulnerability chain via a crafted Apache Tapestry complex-direct request to invoke privileged ConfigEditor components through the public Home page. On version 26 of the affected software, the module reconfigures external user lookup to use an H2 JDBC URL whose initialization SQL evaluates Groovy code. On versions 24 and 25, it uses a bundled Derby procedure to write a temporary Groovy bootstrap class to the application classpath and then loads it as a database driver. Due to the way the vulnerability chain is exploited, the command output cannot be reliably in-band through the existing lookup response, so OSCI agent commands will be marked as blind, meaning that no command output will be returned.
Exploit Platform
Product Name