CVE-2026-6180 Details
Description
A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence reset notification fails to reach the server, the server may reject the initial data chunk while erroneously accepting subsequent chunks before a connection reset completes. This leads to the registration of a truncated badge ID string. While this typically results in an authentication failure, the vulnerability is compounded in environments utilizing custom badge-ID post-processing scripts. In such configurations, the truncated string may be transformed into a valid ID belonging to a different user, leading to unauthorized session establishment (Incorrect User Login) on the device.
A race condition vulnerability has been identified in PaperCut MF, specifically when processing badge-swipe data from certain HP multifunction devices. This issue arises under particular network conditions that involve dropped packets and out-of-order sequence counters, leading the server to mismanage fragmented data. If a sequence reset notification does not reach the server, it may reject the initial data chunk while incorrectly accepting later ones before the connection reset is complete. This flaw results in a truncated badge ID being registered. Although this usually causes an authentication failure, the problem is exacerbated in environments that use custom badge-ID post-processing scripts. In these cases, the truncated ID can be altered to resemble a valid ID of a different user, allowing unauthorized access to the device.
Users are advised to upgrade to PaperCut MF version 25.0.11 or later. For those using the Ricoh Embedded App with PaperCut Hive, version 2.2.0 or later should be installed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.papercut.com/kb/Main/papercut-ng-mf-and-papercut-hive-security-bulletin-may-2026/ | PaperCut | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
| CWE-20 | Improper Input Validation | PaperCut |
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | PaperCut |
Affected Products
| Product | Versions |
|---|---|
| papercut papercut mf | < 24.1.9 >= 25.0.2, < 25.0.10 |
CPE
Remediation
| |
| papercut papercut ng | < 24.1.9 >= 25.0.2, < 25.0.10 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | PaperCut |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 5, 2026 | New CVE Received | PaperCut |