CVE-2026-82077
EUVD-2026-8581124.09.2026, 07:16
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
Awaiting analysis
This vulnerability is currently awaiting analysis.