CVE-2026-82077EPSS p53.0%
CVE-2026-82077CVE-2026-82077
Description
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
Scoring
| EPSS | 0.74% probability of exploitation · percentile 53.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-25 |