← All CVEs

CVE-2023-27351

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2026-04-20Remediation due 2026-05-04

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

7.5
CVSS
78.1%
EPSS (exploit prob.)
100th
EPSS percentile
2023-04-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
papercutpapercut_mf>= 15.0, < 20.1.7
papercutpapercut_mf>= 21.0.0, < 21.2.11
papercutpapercut_mf>= 22.0.0, < 22.0.9
papercutpapercut_ng>= 15.0, < 20.1.7
papercutpapercut_ng>= 21.0.0, < 21.2.11
papercutpapercut_ng>= 22.0.0, < 22.0.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-27351