SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP PaperCut NG/MF authentication bypass attempt
This rule looks for HTTP requests to the PaperCut application that contain the "service=direct" parameter followed by a public page identifier ("Error", "Exception", or "Home") and a privileged component path such as "ConfigEditor" or "UserList". Successful exploitation allows an unauthenticated attacker to invoke administrative functionality on the server.
This rule fires on attempts to bypass authentication in PaperCut NG/MF web applications.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2026-81578 |
Loading description
|
CVE-2026-82078 |
Loading description
|