Skip to content

PaperCut NG/MF Critical Zero-Day Exploited in the Wild - #2765

Open
carlospolop wants to merge 1 commit into
masterfrom
update_PaperCut_NG_MF_Critical_Zero-Day_Exploited_in_th_2ad2a5e201fe3647
Open

PaperCut NG/MF Critical Zero-Day Exploited in the Wild#2765
carlospolop wants to merge 1 commit into
masterfrom
update_PaperCut_NG_MF_Critical_Zero-Day_Exploited_in_th_2ad2a5e201fe3647

Conversation

@carlospolop

Copy link
Copy Markdown
Collaborator

🤖 Automated Content Update

This PR was automatically generated by the HackTricks News Bot based on a technical blog post.

📝 Source Information

🎯 Content Summary

Overview

Rapid7 describes an actively exploited zero-day chain affecting PaperCut NG and PaperCut MF. PaperCut disclosed the emergency on August 27, 2026 after confirming customer incidents, and assigned CVE-2026-81578 and CVE-2026-82078 on August 28, 2026. PaperCut considers all versions potentially impacted, with internet-accessible PaperCut Application Servers at the greatest risk....

🔧 Technical Details

Apache Tapestry displayed-page versus component-page authorization bypass: In applications that expose Tapestry complex-direct requests, determine whether the route independently identifies a displayed page and the page owning the executed component. If authorization is checked only against the displayed page, select an unauthenticated page such as an error, exception, login, or home page while invoking a component belonging to a restricted administrative page. A generalized request pattern is /app?service=direct/<arbitrary-value>/<public-page>/<privileged-page>/<component>. Test every public page rather than only known error pages, because denylist-based fixes may be bypassed by substituting another accessible page.


Converting configuration access into a database execution primitive: When an authorization bypass exposes database-integration settings, identify properties controlling the JDBC driver, JD...

🤖 Agent Actions

Implemented the HackTricks update.

Changes

  • Added src/network-services-pentesting/pentesting-web/apache-tapestry.md
    • Complex-direct component authorization bypass
    • PaperCut request examples
    • Configuration-to-JDBC execution chaining
    • Derby-to-H2/Nashorn execution path
    • Patch-bypass testing guidance
    • Numbered citations to primary sources
  • Linked the page from the web pentesting methodology index.

Validation

  • Internal links and required banners verified.
  • Reference URLs returned HTTP 200.
  • Forbidden sources absent.
  • git diff --check passed.
  • mdbook build skipped because mdbook is not installed.

This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.

@carlospolop

Copy link
Copy Markdown
Collaborator Author

🔗 Additional Context

Original Blog Post: https://rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild

Content Categories: Based on the analysis, this content was categorized under "Network Services Pentesting > 80,443 - Pentesting Web Methodology > Apache Tapestry; cross-reference Pentesting Web > Login Bypass and Java/JDBC database-to-RCE techniques".

Repository Maintenance:

  • MD Files Formatting: 998 files processed

Review Notes:

  • This content was automatically processed and may require human review for accuracy
  • Check that the placement within the repository structure is appropriate
  • Verify that all technical details are correct and up-to-date
  • All .md files have been checked for proper formatting (headers, includes, etc.)

Bot Version: HackTricks News Bot v1.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant