HomeCyber BalkansMetasploit Introduces Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

Metasploit Introduces Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

Published on

spot_img

Rapid7 is gearing up to enhance its Metasploit Framework by introducing an exploit module specifically aimed at addressing a series of vulnerabilities impacting PaperCut MF and PaperCut NG. These vulnerabilities have been identified as actively exploited in the wild, prompting the need for robust security responses, particularly involving print management servers. The initiative represents a critical step in providing public offensive tools to manage the current security emergency associated with these widely used applications.

The newly proposed exploit module targets two specific vulnerabilities: CVE-2026-81578 and CVE-2026-82078. Both vulnerabilities have been found to allow attackers to achieve remote code execution on vulnerable PaperCut Application Servers, creating significant risks for users and organizations relying on these systems. The role of the Metasploit Framework in this situation becomes even more pivotal, as it enables security professionals to simulate attacks and better understand potential threats, thereby enhancing their response strategies.

The module, which is submitted as pull request #21842, is currently open for review and has already received positive feedback from reviewers. It comprises 845 lines of code spread across four different files and is compatible with PaperCut MF and NG versions 24.x, 25.x, and 26.x. This compatibility is crucial, as it ensures that a wide range of users can leverage the new tool for defensive measures. Named multi/http/papercut_ng_external_user_lookup_rce, the module includes comprehensive documentation and features a version-based check routine that assists authorized personnel in identifying vulnerable instances effectively.

The characteristics of the vulnerabilities in question are concerning. CVE-2026-81578 is categorized as an authentication-bypass issue found in the web management interface, with a high severity rating of 8.8. This flaw enables unauthenticated remote requests to execute backend administrative functions, including the modification of critical configuration settings. On the other hand, CVE-2026-82078 has been rated as critical with a severity score of 9.4, identified as an unsafe dynamic class-loading vulnerability within PaperCut’s database connection utilities. When combined, these vulnerabilities can facilitate unauthorized changes to external user-lookup configurations and allow attackers to execute code within the PaperCut server process.

Rapid7 has disclosed that these vulnerabilities were flagged as a zero-day exploit chain that has been actively leveraged by malicious actors. PaperCut has also confirmed that its customers have been affected and noted that all versions of both PaperCut NG and MF may potentially be at risk.

The immediate threat landscape is particularly worrisome for Application Servers that expose their web interfaces to the public internet. The exploit chain begins with direct web access, underscoring the importance of implementing proper security measures. According to the details provided in the pull request, the exploit module is designed to support platform-agnostic Java payloads and command payloads for both Windows and Linux environments.

Java payload execution depends on the specific product version; the module is capable of executing Java payloads in memory for version 26.x, while earlier versions (25.x and below) necessitate a helper class, illustrating varying execution approaches across product iterations. The contributor of the module ran tests against PaperCut MF 26.0.4 and PaperCut NG 24.1.9, although they acknowledged that older, unsupported releases may also be vulnerable, despite not conducting direct tests on those versions.

It is worth noting that the module is reported to bypass PaperCut’s first emergency patch, creating a significant security gap. However, Rapid7 confirmed that the second emergency patch issued by the vendor effectively mitigates the exploit pathway. It is critical for organizations to recognize this distinction: those that only applied the initial patch do not possess adequate protection and are strongly urged to implement the second emergency patch without delay.

PaperCut has taken proactive steps by releasing this second patch for versions 24, 25, and 26 following extensive analysis in collaboration with both internal staff and external researchers. Administrators are advised to restrict PaperCut web access to trusted IP ranges and apply the second emergency patch on primary Application Servers and any relevant secondary servers. They should also conduct thorough investigations for any signs of compromise, as PaperCut has outlined several warning indicators that could signal an active threat, such as unexplained pc-app child processes, anomalies in server.log files, unexpected database-driver errors, and any signs of remote access software installations that were not planned.

The impending availability of the Metasploit module significantly lowers the barriers for reliable exploitation, thus elevating the urgency for rapid threat mitigation and hunting efforts for all exposed PaperCut deployments. Security professionals are now faced with a crucial opportunity to bolster their defenses and mitigate the risks associated with these vulnerabilities before they can be leveraged for malicious purposes.

Source link

Latest articles

Aurora Ransomware Operators Utilize Cursor AI to Attack Ten Targets

Ransomware Threat Actors Harness AI Tools for Cyber Attacks Recent investigations by cybersecurity firms CloudSEK...

Texas: A Testing Ground for White House Water Cybersecurity Initiatives

Watershed 250 Initiative Unveils Free Cybersecurity Resources for Small Water Utilities in Texas In a...

Judge Rules Pentagon’s Anthropic Measures are Illegal

A federal judge has recently ruled that the Pentagon acted unlawfully in designating the...

More like this

Aurora Ransomware Operators Utilize Cursor AI to Attack Ten Targets

Ransomware Threat Actors Harness AI Tools for Cyber Attacks Recent investigations by cybersecurity firms CloudSEK...

Texas: A Testing Ground for White House Water Cybersecurity Initiatives

Watershed 250 Initiative Unveils Free Cybersecurity Resources for Small Water Utilities in Texas In a...

Judge Rules Pentagon’s Anthropic Measures are Illegal

A federal judge has recently ruled that the Pentagon acted unlawfully in designating the...