CVE-2026-4794 Details
Description
Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's authenticated context (e.g. requires an active login session).
A cross-site scripting (XSS) vulnerability has been identified in PaperCut NG/MF versions prior to 25.0.10. This vulnerability allows authenticated administrator users to inject arbitrary web scripts or HTML into various UI fields. Exploitation of this issue could compromise the sessions of other administrators or enable unauthorized actions within the context of an administrator's active login.
Users are advised to upgrade to PaperCut NG/MF version 25.0.10. For Konica Minolta fleets using PaperCut MF, ensure the embedded application is updated to version 25.0.5 (Standard) or 25.0.9 (Certified).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-march-2026/ | PaperCut | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | PaperCut |
Affected Products
| Product | Versions |
|---|---|
| papercut papercut mf | < 25.0.10 |
CPE
Remediation
| |
| papercut papercut ng | < 25.0.10 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | PaperCut |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | PaperCut |