
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
Professional security research tool for PaperCut NG/MF vulnerability assessment & authorized exploitation
╔══════════════════════════════════════════════════════════════════╗
║ PAPERCUT SECURITY TOOL – POWER MODE ║
║ CVE-2026-81578 · CVE-2026-82078 · v3.1.0 ║
║ ⚡ powered by yora 1928 ⚡ ║
╚══════════════════════════════════════════════════════════════════╝
This tool provides safe, non‑destructive vulnerability assessment and optional remote exploitation (with explicit authorization) for PaperCut NG/MF servers.
It is designed for security researchers, penetration testers, and blue‑team defenders who need to validate the presence of two critical PaperCut vulnerabilities.
| CVE ID | Description | CVSS | CWE |
|---|---|---|---|
| CVE-2026-81578 | Authentication Bypass via Apache Tapestry "complex direct" requests | 8.8 (HIGH) | CWE-306 |
| CVE-2026-82078 | Unsafe Dynamic Class Loading in Database Connection Utilities | 9.4 (CRITICAL) | CWE-470 |
Key references:
This tool performs indicator‑based remote detection. It does not claim to prove exploitability on real PaperCut servers unless --force is used with explicit written authorization.
| Status | Meaning |
|---|---|
SAFE | Version is fixed or no indicators detected |
AFFECTED_VERSION | Version matches the affected range (vendor advisory) |
TAPESTRY_DETECTED | Apache Tapestry framework detected (used by PaperCut) |
ADMIN_ENDPOINT_ACCESSIBLE | Administrative endpoints are accessible without auth |
DB_CONFIG_ACCESSIBLE | Database configuration endpoints are accessible |
POTENTIALLY_VULNERABLE | Combination of indicators suggests possible vulnerability, but exploitability is not verified |
NOT_DETECTABLE | Insufficient information to assess |
Confidence scores are calculated based on the weight of evidence and are capped at 85% for remote detection to avoid over‑claiming.
--force flag (authorization required)--input, --threads)--prefilter)| Feature | Against Real Target | Against Local Lab |
|---|---|---|
| Fingerprinting | ✅ Safe (read‑only) | ✅ Safe |
| CVE Assessment | ✅ Safe (indicator‑based) | ✅ Safe |
| Concept Demonstration | ❌ BLOCKED (localhost only) | ✅ Allowed |
| Remote Exploitation | ⚠️ Requires --force & authorization | ✅ Allowed |
| Configuration Changes | ❌ Never | ✅ Only within lab |
| RCE / Payload Execution | ❌ Never | ❌ Not implemented (simulated only) |
# Clone the repository
git clone https://github.com/yourusername/papercut-cve-tool.git
cd papercut-cve-tool
# Create virtual environment
python3 -m venv .venv
source .venv/bin/activate # Linux/macOS
# or
.venv\Scripts\activate # Windows
# Install dependencies
pip install -r requirements.txt
# Verify installation
python papercut.py self-test
# Show help
python papercut.py --help
# Run a full scan against a target
python papercut.py scan http://127.0.0.1:8080
# Fingerprint only
python papercut.py fingerprint http://127.0.0.1:8080
# Check a specific CVE
python papercut.py check http://127.0.0.1:8080 --cve 81578
# Start the educational local lab
python papercut.py lab
# Run concept demonstration (lab only)
python papercut.py exploit --cve 81578
# Remote exploit (AUTHORIZATION REQUIRED)
python papercut.py exploit --cve 81578 --target https://target.com:9192 --force
# Batch scan with prefilter and threading
python papercut.py scan --input targets.txt --prefilter --threads 10 --timeout 5
# Analyze log file for IOCs
python papercut.py detect server.log
# Generate HTML report
python papercut.py report result.json --format html
# Interactive menu
python papercut.py interactive
| Command | Description |
|---|---|
scan TARGET | Full vulnerability scan with fingerprinting + CVE checks |
fingerprint TARGET | Detect PaperCut version, Tapestry framework, and exposed endpoints |
check TARGET --cve {81578,82078} | Run a specific CVE indicator check |
lab [--port PORT] [--test] | Start the educational local lab (with optional self‑test) |
exploit --cve {81578,82078} [--target] [--force] | Run concept demonstration or remote exploit (if authorized) |
detect LOGFILE [--output] | Analyse log file for suspicious indicators |
report INPUT [--format {html,json,text}] [--output] | Generate professional report from JSON results |
interactive | Launch interactive menu |
self-test | Run internal diagnostics |
| Option | Description |
|---|---|
--timeout N | Request timeout in seconds (default: 10) |
--verbose | Show detailed debug output |
--quiet | Suppress non‑essential output |
--output FILE | Save results to file |
--format {text,json,html} | Output format for scan/report |
| Option | Description |
|---|---|
--input FILE | File with targets (one per line) for batch scanning |
--output-dir DIR | Directory to save batch results |
--threads N | Number of concurrent threads (batch mode) |
--prefilter | Check open ports before scanning (batch only) |
The lab is a minimal Python HTTP server that reproduces the concepts of both vulnerabilities for educational purposes.
ConfigEditor, UserList) while displaying a public page (Error.page, Exception.page)# Start the lab
python papercut.py lab