Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4064 articles · 206061 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-6645EXPLOITEDPATCHED
papercut · papercut print deploy

Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows

Description

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.

Affected Products

VendorProductVersions
papercutpapercut print deploy0

References

  • https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-june-2026/

Related News (2 articles)

Tier C
VulDB70d ago
CVE-2026-6645 | PaperCut Print Deploy up to 1.10.4177 on Windows pc-printer-updater.exe uncontrolled search path (EUVD-2026-38209)
→ No new info (linked only)
Tier B
CERT-FR70d ago
Vulnérabilité dans PaperCut Print Deploy Client (22 juin 2026)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.10.4178
CWECWE-427
PublishedJun 22, 2026
Last enriched69d agov3
Tags
CVE-2026-6645
Trending Score0
Source articles2
Independent2
Info Completeness9/14
Missing: cvss, epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (4)

NONECVE-2026-81578EXPKEV
PaperCut MF/NG: Authentication Bypass
Trending: 120
NONECVE-2026-82078EXPKEV
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
Trending: 79
NONECVE-2026-8793
PaperCut NG/MF: Insufficient brute-force protection
Trending: 2
NONECVE-2026-8794
PaperCut NG/MF: User enumeration via timing attack
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 22, 2026
Discovered by ZDM
Jun 22, 2026
Updated: affectedVersions, severity, tags
Jun 22, 2026
Updated: affectedVersions, severity, exploitAvailable, activelyExploited
Jun 22, 2026
Actively Exploited
Jun 23, 2026
Exploit Available
Jun 23, 2026
Patch Available
Jun 23, 2026

Version History

v3
Last enriched 69d ago
v3Tier B69d ago

Updated affected versions to include versions prior to v2699, changed severity to CRITICAL, and marked exploit as available and actively exploited.

affectedVersionsseverityexploitAvailableactivelyExploited
via CERT-FR
v2Tier C70d ago

Updated affected versions to include 1.10.4177, changed severity to HIGH, and noted that no exploit is available.

affectedVersionsseveritytags
via VulDB
v170d ago

Initial creation