๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability
Summary
PaperCut NG/MF has an improper authentication vulnerability that allows remote attackers to bypass authentication (skipping the normal login process) through a flaw in the SecurityRequestFilter class. This vulnerability is actively being exploited by attackers in the real world.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Details
EPSS: 44.6%
Yes
๐ฅ Actively Exploited
April 19, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-27351
First tracked: April 20, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%