{"id":"CVE-2026-14780","published":"2026-09-24T06:17:00.567","lastModified":"2026-09-25T04:17:34.103","description":"A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime sandbox.  \n\nA successful execution enables an attacker to run unauthorized operating system commands with administrative privileges on the host operating system.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-sep-2026/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}