{"id":"CVE-2026-82077","published":"2026-09-24T07:16:33.457","lastModified":"2026-09-25T04:17:47.677","description":"An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-22","CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://www.papercut.com/kb/Main/security-bulletin-sep-2026/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}