29 August 2026
Reference: CVE-2023-27350
1. What is being reported?
Researchers have discovered a critical vulnerability in PaperCut NG version 22.0.5 that allows attackers to skip the usual login process. This means someone could remotely access the system and run commands with full system privileges, potentially taking over the device or network.
2. What this means in plain English
If your organisation uses PaperCut NG 22.0.5, this flaw could let hackers break in without any credentials and cause serious damage, such as stealing data or disrupting services. This is especially risky because the attack can happen remotely and does not require the attacker to be inside your network.
3. Could this affect a small business?
Small businesses, charities, clubs, or other organisations using PaperCut NG 22.0.5 are at risk. Those not using this software or using a different version are likely not affected. If you are unsure whether you use this software, check with your IT provider.
4. What to do now
- Check if your organisation uses PaperCut NG version 22.0.5.
- If you do, contact your software supplier or IT provider immediately to apply any available security updates or patches.
- If no patch is available yet, ask your IT provider about temporary measures to block unauthorised access to the software.
- Review your network security settings to limit external access to print management systems.
5. Ask your IT provider
Can you confirm if our PaperCut NG software is version 22.0.5 and, if so, have the latest security updates been applied to protect against the recent critical vulnerability CVE-2023-27350?
6. Bottom line
If you use PaperCut NG 22.0.5, act quickly to update or secure it to prevent hackers from gaining full control of your system.
Information based on NVD, CISA KEV, and reputable security reports.