Critical Analysis: CVE-2023-27351 - PaperCut NG/MF Improper Authentication Vulnerability... — April 24, 2026

Published 24 Apr 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

Initial Discovery and Context Alright, let’s dig into CVE-2023-27351. When this vulnerability popped on April 24, 2026, it immediately registered as a significant issue for us here at AGMP Partners, primarily because PaperCut NG/MF is so pervasive across enterprise networks. We’re talking print management software, which often sits deep in the network, managing sensitive user and document data. The initial disclosures highlighted an improper authentication vulnerability, essentially allowing unauthenticated attackers to bypass authentication and execute arbitrary code on the PaperCut Application Server. This isn't your average printer vulnerability; this is a full-blown compromise of a critical backend system. The affected versions are wide-ranging: PaperCut NG/MF 8.0 up to 11.1.2 (for macOS), 12.0 up to 20.1.7 (for Windows and macOS), and 21.0 up to 22.0.5 (for Windows and macOS). That'