CVE-2026-5115 Details
Description
The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedded application is a software interface that runs directly on the touch screen of a multi-function device. It was internally discovered that the communication channel between the embedded application and the server was insecure, which could leak data including sensitive information that may be used to mount an attack on the device. Such an attack could potentially be used to steal data or to perform a phishing attack on the end user.
A session hijacking vulnerability has been identified in the PaperCut NG/MF embedded application for Konica Minolta devices. The issue arises from an insecure communication channel between the embedded application and the PaperCut Application Server, which could be exploited to intercept sensitive data or conduct phishing attacks on end users. This vulnerability affects PaperCut NG/MF versions prior to 25.0.10, as well as PaperCut MF versions prior to 25.0.5 (Standard Release) or 25.0.9 (Konica Minolta Certified Release).
Users are advised to upgrade to PaperCut MF 25.0.5 (Standard Release) or 25.0.9 (Konica Minolta Certified Release). After upgrading the Application Server, ensure that the embedded application on Konica Minolta devices is also updated to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-march-2026/ | PaperCut | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | PaperCut |
Affected Products
| Product | Versions |
|---|---|
| papercut papercut mf | < 25.0.5 |
CPE
Remediation
| |
| papercut papercut mf konica minolta | < 25.0.9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | PaperCut |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | PaperCut |