Safeguard
Vulnerability Analysis

A Second PaperCut Authentication Bypass, This One Tied to Ransomware

CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.

Safeguard Research Team
4 min read

PaperCut NG/MF's SecurityRequestFilter class contains an improper authentication vulnerability, CVE-2023-27351, that lets a remote, unauthenticated attacker bypass authentication entirely — a distinct finding from the PaperCut CVEs already covered elsewhere in this series, and one CISA flags with a confirmed ransomware association.

An additional PaperCut finding, not the whole story

This is not the same PaperCut vulnerability discussed in an earlier post in this series; CVE-2023-27351 is a separate, independently disclosed bug against the SecurityRequestFilter authentication mechanism, added to CISA's KEV catalogue on 20 April 2026 with a due date of 4 May 2026. That two distinct PaperCut CVEs both warrant coverage in a single vulnerability-tracking series says something about the product's overall attack surface: PaperCut NG/MF is enterprise print management software, deployed widely enough and exposed to the internet often enough that multiple, unrelated authentication and access-control weaknesses have each independently drawn real-world exploitation.

Why this specific bug is unusually dangerous despite its "only" 7.5 score

CVE-2023-27351 carries a CVSS score of 7.5 — high, but not the 9.x range that typically triggers the most urgent internal alarm — yet CISA's own data flags it with known ransomware campaign use, which should override whatever priority a raw CVSS number alone would suggest. The vulnerability results from what NVD describes as "improper implementation of the authentication algorithm" within the SecurityRequestFilter class, and requires no authentication whatsoever to exploit: an attacker with no credentials at all can bypass PaperCut's authentication mechanism outright. That combination — no authentication required, plus a documented ransomware association — is precisely the profile CISA's KEV catalogue exists to flag, because CVSS scoring reflects theoretical technical severity while KEV inclusion reflects confirmed, observed attacker behavior, and the two don't always agree on which bugs deserve the most urgent attention.

The Zero Day Initiative advisory referenced in this CVE's disclosure (ZDI-CAN-19226) indicates the bug was found and reported through a structured responsible-disclosure program well before its public NVD entry in April 2023, meaning defenders have had roughly three years to patch against it before its ransomware association pushed it into KEV. That gap between disclosure and confirmed-exploited status mirrors a pattern seen repeatedly across this series: vulnerabilities with a working, documented fix available for years still get caught up in ransomware operations against organizations that never applied it, because unpatched authentication bypasses in widely deployed enterprise software remain reliably exploitable for as long as unpatched instances exist on the internet.

Print management as an underrated ransomware entry point

Print servers occupy an unusual position in enterprise networks: often deployed years ago by IT staff who have since moved on, rarely subjected to the same security review cadence as domain controllers or email servers, yet frequently granted broad network reach because printing needs to work from every department and every floor. An authentication bypass in software occupying that position gives a ransomware operator a foothold that's both easy to reach — print servers are commonly internet-facing for remote or branch-office printing — and easy to overlook during routine vulnerability triage, precisely because "the print server" doesn't intuitively register as high-value infrastructure the way a database or identity provider does.

What to check this week

Confirm whether the organization's PaperCut NG/MF deployment has ever been patched against CVE-2023-27351 specifically, distinct from any patching already applied for the other PaperCut CVE covered earlier in this series — the two are unrelated bugs requiring unrelated fixes.

Treat any internet-facing PaperCut instance as a priority regardless of its perceived business importance, given this vulnerability's confirmed ransomware association and its requirement of zero authentication to exploit.

Review PaperCut server logs for unexplained authentication or administrative activity predating any known patch date, since a documented ransomware association means this bug has already been used as an initial foothold in real intrusions, not merely demonstrated in a lab.

Apply PaperCut's official remediation guidance referenced in PO-1216 and PO-1219 rather than a partial mitigation, since an incomplete fix to an authentication algorithm bug of this kind can leave bypass paths intact.

A final consideration on infrastructure that outlives its original deployment team

PaperCut, like many pieces of infrastructure installed once and rarely revisited, illustrates a recurring theme in ransomware-associated KEV entries: the vulnerability itself is often old and the fix long available, but the organizational memory of who owns that specific server, and whether it's ever been patched, has quietly faded in the years since.

How Safeguard helps

Safeguard's continuous inventory surfaces infrastructure like print management servers that tend to fall outside routine security review, and flags CISA's confirmed-ransomware designation specifically so a 7.5-scored bug with real-world criminal use doesn't get deprioritized behind higher-CVSS findings with no documented exploitation.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.