Known vulnerability record

CVE-2023-27351

PaperCut NG/MF Improper Authentication Vulnerability

Stable IDcve:CVE-2023-27351Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

Keep the signals separate

CVSS severityhighScore 8.2 · source zdi
EPSS probability77.4%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-20
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2023-04-20
CVE modified
2026-04-21
KEV date added
2026-04-20
Dataset fetched
2026-08-21T03:55:03.222Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.