Known vulnerability record
CVE-2023-27351
PaperCut NG/MF Improper Authentication Vulnerability
Summary
PaperCut NG/MF Improper Authentication Vulnerability
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
Signals
Keep the signals separate
CVSS severityhighScore 8.2 · source zdi
EPSS probability77.4%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-20
Ransomware useknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2023-04-20
- CVE modified
- 2026-04-21
- KEV date added
- 2026-04-20
- Dataset fetched
- 2026-08-21T03:55:03.222Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2023-27351 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2023-27351 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27351 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.