# PaperCut NG/MF patches confidentiality flaws

Published: 2026-08-03 · Severity: medium
Canonical: https://vorant.io/reports/a0fdb1bc-e013-5c56-aabe-0158bcf84d4a/papercut-ng-mf-patches-confidentiality-flaws

> Two vulnerabilities in PaperCut NG/MF before 26.0.3 allow attackers to breach data confidentiality and bypass security policy.

CERT-FR issued an advisory covering two vulnerabilities in PaperCut NG/MF print management software affecting versions prior to 26.0.3. The flaws, tracked as CVE-2026-8793 and CVE-2026-8794, could allow an attacker to compromise data confidentiality and bypass the application's security policy enforcement.

PaperCut has released a security bulletin along with patches addressing these issues. No evidence of active exploitation is mentioned in the advisory; organizations running affected versions are advised to consult the vendor bulletin and apply the available fixes.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8793, CVE-2026-8794

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0959

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a0fdb1bc-e013-5c56-aabe-0158bcf84d4a/papercut-ng-mf-patches-confidentiality-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
