LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 20, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 4, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-27351 to its Known Exploited Vulnerabilities catalog on Apr 20, 2026, with a federal patch deadline of May 4, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

PaperCut NG/MF contains an improper authentication vulnerability that allows remote attackers to bypass authentication controls on affected installations. The issue is tracked as CVE-2023-27351 and has been observed in ransomware campaigns, which increases the urgency for organizations that rely on this print-management software.

How it works

The weakness is classified as CWE-287 (Improper Authentication). An attacker can reach the SecurityRequestFilter class and circumvent the normal authentication checks that the application expects to enforce before granting access to administrative or sensitive functions. No specific exploit steps are provided in the available information; defenders should treat any unauthenticated remote access attempt against the PaperCut web interface or related endpoints as suspicious until the vendor advisory is reviewed in full.

Am I affected? How to find it in your systems

PaperCut NG and MF are typically deployed on-premises as print-server or print-management platforms. Begin by locating all instances through asset inventories, network scans for known PaperCut ports and services, and configuration-management databases. Compare installed versions and configurations against the vendor advisory, because the vulnerability affects specific releases and setups. Review web-access logs and authentication logs for anomalous requests that reach protected resources without prior credential validation; any such activity should be investigated promptly.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review authentication-related settings in the PaperCut console and confirm that the SecurityRequestFilter and associated controls are operating as intended. For the broader class of improper-authentication issues, enforce least-privilege access, require strong network-level authentication where possible, and disable unnecessary remote management interfaces.

If you can't patch immediately

If your data may have been exposed

Because this vulnerability has been used in ransomware operations, any successful exploitation could lead to data exposure or further compromise. Organizations can run a free exposure scan of their domains and email addresses against known breach datasets to determine whether their information appears in publicly reported incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPaperCut · NG/MF
WeaknessCWE-287
Added to CISA KEVApr 20, 2026
Federal patch deadlineMay 4, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities