CVE-2023-27351: Authentication Bypass in PaperCut NG, Actively Exploited
High-severity vulnerability (CVSS 7.5) in PaperCut NG allows access without credentials. Listed in CISA's KEV catalog. Update now.
CVE-2023-27351: Authentication Bypass in PaperCut NG, Actively Exploited
In short
PaperCut NG 22.0.5 (Build 63914) contains a serious flaw that allows a remote attacker to access the print management system without needing a username or password [1]. The vulnerability, identified as CVE-2023-27351, has a CVSS score of 7.5 (high severity according to NVD) [1] and is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [2], confirming that it has been used in real-world attacks. If your organization uses PaperCut NG, the priority action is to apply the vendor's update immediately.
What it is and why it matters
PaperCut is one of the most widely used print management platforms in corporate, educational, and healthcare environments. CVE-2023-27351, published on April 20, 2023 [1], exposes a design flaw in the SecurityRequestFilter class of PaperCut NG: the authentication logic is implemented incorrectly, allowing an external attacker to bypass it completely without presenting any credentials at all [1].
In business terms, this means that anyone with network access to the PaperCut server could interact with the print administration panel as if they were a legitimate administrator. Credential-free access to print management systems can expose queued documents, internal network configurations, user data, and, depending on the environment, serve as an entry point into broader corporate systems.
Our intelligence team at OCIRIA classifies this vulnerability as critical in terms of operational risk, an in-house assessment that reflects the potential impact on real business environments and goes beyond the official numerical NVD score (CVSS 7.5, high severity) [1]. This distinction matters: the NVD score measures technical characteristics of the flaw; our assessment also factors in confirmed active exploitation [2] and the product's prevalence across critical infrastructure.
Who is affected
The official NVD description identifies PaperCut NG 22.0.5 (Build 63914) as the affected version [1]. If your organization uses this specific version of the product from vendor PaperCut, you should consider yourself at risk until the corresponding patch is applied.
Particularly exposed profiles:
- Businesses with managed printer fleets served from a network-accessible PaperCut server.
- Educational institutions and universities, where PaperCut is very commonly used.
- Healthcare environments and public administration with centralized printing infrastructure.
- Organizations where the PaperCut server is exposed, even partially, to networks that are not fully isolated.
How to know if you are vulnerable
The first step is to identify whether PaperCut NG is installed in your infrastructure and the exact version and build running in production. Version information is usually available in the PaperCut administration panel itself, or by checking with the team responsible for print management systems.
Specifically check whether the installed version is 22.0.5, Build 63914 [1]. In addition, it is worth reviewing:
- Whether the PaperCut administration port is accessible from networks other than the internal management network.
- Whether there are any anomalous recent access attempts or connections in the print server logs.
- Whether the PaperCut server is exposed, directly or indirectly, to the Internet.
Reviewing your infrastructure's exposed attack surface is key to understanding the real scope of the risk in your specific case.
How to protect yourself
1. Update PaperCut NG immediately. Apply the fixed version made available by vendor PaperCut. Check PaperCut's official update channel and follow its installation instructions.
2. Restrict access to the administration panel. Limit exposure of the PaperCut server to strictly necessary networks and users through firewall rules or network segmentation.
3. Review access logs. Since the vulnerability is listed in CISA's KEV catalog [2], exploitation in real-world environments is confirmed. Analyze recent access to the print server for signs of unauthorized activity.
4. Set up monitoring alerts. Configure alerts for unusual access or unexpected configuration changes in the PaperCut system.
5. Communicate with business stakeholders. If the update process requires a maintenance window, inform leadership of the existing risk so an informed decision can be made about urgency.
Frequently asked questions
Does the attacker need access to the internal network?
Not necessarily. If the PaperCut server has some form of external exposure, or the attacker is already inside the corporate network, no credentials are required to exploit the flaw [1].
Does it also affect PaperCut MF?
The official NVD description explicitly references PaperCut NG 22.0.5 (Build 63914) [1]. Our internal radar indicates that the context of the flaw may also be relevant to MF environments, but we recommend consulting PaperCut's official security advisories directly to confirm the exact scope for your installation.
What does it mean that it's listed in CISA's KEV catalog?
CISA's Known Exploited Vulnerabilities (KEV) catalog compiles vulnerabilities for which there is evidence of active real-world exploitation [2]. Its inclusion in that list is not theoretical: it indicates that the vulnerability has been used in documented attacks, which raises the urgency of taking action.
Is patching enough?
Applying the update closes the attack vector, but it is also advisable to conduct a review of historical access to rule out the possibility that the vulnerability was exploited before you applied the patch.
Sources
- [1] NVD — Official record for CVE-2023-27351: nvd.nist.gov/vuln/detail/CVE-2023-27351
- [2] CISA — Known Exploited Vulnerabilities (KEV) Catalog: cisa.gov/known-exploited-vulnerabilities-catalog