CVE-2026-14780
NONE—CVSS v3
—CVSS v2
0.31%
EPSS (exploit probability)
CWE-94CWE
Description
A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.
A successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.
Affected routers (0)
No routers currently mapped to this CVE in our database.