Vulnerabilities

CVE-2023-27351

PaperCut NG/MF Improper Authentication Vulnerability

Actively exploited (CISA KEV) Used in ransomware campaigns High 7.5 CVSS 3.1

Description

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

Description as published by the source, in English.

Key facts

Published
2023-04-20
Last modified
2026-06-17
Assigned by
zdi-disclosures@trendmicro.com
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Scored by
nvd@nist.gov (NVD Primary)
Probability of exploitation
77.4 % among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Not registered in the sources

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-04-20, with a remediation deadline of 2026-05-04 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Papercut Papercut Mf ≥ 15.0, < 20.1.7 Affected
Papercut Papercut Mf ≥ 21.0.0, < 21.2.11 Affected
Papercut Papercut Mf ≥ 22.0.0, < 22.0.9 Affected
Papercut Papercut Ng ≥ 15.0, < 20.1.7 Affected
Papercut Papercut Ng ≥ 21.0.0, < 21.2.11 Affected
Papercut Papercut Ng ≥ 22.0.0, < 22.0.9 Affected

Weakness type

  • CWE-287: Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack techniques

Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.

  • T1040: Network Sniffing credential-access, discovery
  • T1134: Access Token Manipulation stealth, privilege-escalation
  • T1185: Browser Session Hijacking collection
  • T1505.003: Web Shell persistence
  • T1548: Abuse Elevation Control Mechanism privilege-escalation
  • T1550.001: Application Access Token lateral-movement
  • T1557: Adversary-in-the-Middle credential-access, collection
  • T1563: Remote Service Session Hijacking lateral-movement

References

Related at Berigo

Articles

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities