EXPOSURES › CVE-2023-27350
CVE-2023-27350
CRITICAL ⌖ ON CISA KEV · EXPLOITEDPaperCut MF/NG suffered an improper access control flaw allowing authentication bypass and system-level code execution.
The SetupCompleted class in PaperCut MF/NG lacks proper access controls, enabling attackers to bypass authentication and execute arbitrary code as the system user. This is a critical failure for DIB organizations because it directly enables remote code execution and data exfiltration, violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must immediately patch PaperCut MF/NG and restrict its network exposure.
Shame score — A critical access control flaw enabling system-level code execution was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.