---
id: CVE-2026-87739
title: "An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated,\_remote attacker to trigger report generation"
summary: "An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated,\_remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and …"
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y'
cwe:
  - CWE-639
vendor: PaperCut
product: PaperCut NG/MF
affected:
  - ng_mf < 25.0.13
  - ng_mf >= 26.0.0 < 26.0.5
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:22.573'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87739'
references:
  - url: 'https://www.papercut.com/kb/Main/security-bulletin-sep-2026/'
    label: eb41dac7-0af8-4f84-9f6d-0272772514f4
tags:
  - nvd
  - cve.org
epss: 0.00378
epssPercentile: 0.29163
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-24T12:42:13.527939Z'
cvssSource: cna
ingestedAt: '2026-09-24T08:40:12.062Z'
---

## Overview

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
