---
id: CVE-2023-27351
title: >-
  This vulnerability allows remote attackers to bypass authentication on
  affected installations of PaperCut NG 22.0.5 (Build 63914)
summary: >-
  This vulnerability allows remote attackers to bypass authentication on
  affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is
  not required to exploit this vulnerability. The specific flaw exists within
  the Security…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-287
vendor: papercut
product: papercut_mf
affected:
  - 'papercut_mf >= 15.0, < 20.1.7'
  - 'papercut_mf >= 21.0.0, < 21.2.11'
  - 'papercut_mf >= 22.0.0, < 22.0.9'
  - 'papercut_ng >= 15.0, < 20.1.7'
  - 'papercut_ng >= 21.0.0, < 21.2.11'
  - 'papercut_ng >= 22.0.0, < 22.0.9'
patched:
  - papercut_mf 22.0.9
  - papercut_ng 22.0.9
published: '2023-04-20'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:17:14.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-27351'
references:
  - url: 'https://www.papercut.com/kb/Main/PO-1216-and-PO-1219'
    label: zdi-disclosures@trendmicro.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-23-232/'
    label: zdi-disclosures@trendmicro.com
  - url: 'https://www.papercut.com/kb/Main/PO-1216-and-PO-1219'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-23-232/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27351
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.78052
epssPercentile: 0.99564
kev: true
kevDateAdded: '2026-04-20'
kevDueDate: '2026-05-04'
kevRansomware: true
exploited: true
exploits:
  nuclei:
    - CVE-2023-27351
  checkedAt: '2026-10-01T19:59:31.752Z'
exploitAvailable: true
zeroDay: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-04-21T03:55:38.095423Z'
scores:
  nvd: 7.5
  cna: 8.2
ingestedAt: '2026-10-01T18:55:42.395Z'
---

## Overview

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

## Affected

- `papercut_mf >= 15.0, < 20.1.7`
- `papercut_mf >= 21.0.0, < 21.2.11`
- `papercut_mf >= 22.0.0, < 22.0.9`
- `papercut_ng >= 15.0, < 20.1.7`
- `papercut_ng >= 21.0.0, < 21.2.11`
- `papercut_ng >= 22.0.0, < 22.0.9`

## Remediation

Upgrade past the affected range:

- `papercut_mf 22.0.9`
- `papercut_ng 22.0.9`
