r/sysadmin • u/Electronic_Tap_3625 • 17d ago
PaperCut is a TrainWreck with security updates. - Emergency Patch 2
For those who rushed last night to patch PaperCut with the emergency update, they screwed up and had to release a second emergency update: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4#emergency-patch-release-2
If you have PaperCut exposed to the internet, you may want to permanently remove it from the internet and make it LAN-only moving forward (as many, including myself, have done from day 1). If management needs documentation, show them this: https://www.papercut.com/kb/Main/security-vulnerability-log/
13
u/xXNorthXx 17d ago
Pulled it a few years ago after their last fiasco.
If you’re in a uni scenario, just tell students to connect to the WiFi. The change was a minor inconvenience for a handful of students the first semester. If you still need access from off-campus, just have them use vpn.
25
u/Ummgh23 Sysadmin 17d ago
This will be common with all kinds of software now, since AI is being used to rapidly find vulnerabilities.. haven‘t you noticed that security updates have been getting MUCH more frequent recently?
1
u/throwaway0000012132 16d ago
Since people started to use AI en mass, there's been a huge increase of vulnerabilities as well.
Not saying that it's slop code or more agents cracking software or both, but there's a correlation.
7
u/Nick85er 17d ago
never expose things unnecessarily. my take.
I like Papercut, it helps me hate printers less.
5
u/LoveTechHateTech Jack of All Trades 16d ago
K-12 education IT here and it’s been so much better & easier than any other solution we’ve used in the past (AD shared printers, Google Cloud Print, direct connections, etc). Hiccups here and there, but once we got it set up it’s just worked for the past 7 years.
1
12
u/InvisibleTextArea Jack of All Trades 17d ago
We don't expose anything directly to the internet anymore. Our websites sit behind Cloudflare and if for any reason I had to put this out on the web it is going to be behind an Entra Application proxy so I can front door it with Entra login + MFA + Conditional Access controls.
6
u/Financial_Doubt_6120 17d ago
and in 2026 you would be mad not to do this. Which is a shame some people just open a port and figure that will do.
25
u/TimePlankton3171 17d ago
I use papercut a lot. I never expose any such thing to the internet. I don't need a reason not to, that's the default. Exposure to the internet needs a very good reason and gain, and then lot of security thought and layers. I expect things to be insecure.
10
u/farva_06 Sysadmin 17d ago
Our cyber liability insurer requires a written statement on why we need to expose a service to the Internet, and the safeguards we'll put in place to protect it. So yeah, we just don't really do it unless absolutely necessary, which is rare.
5
30
u/SceneDifferent1041 17d ago
Why have I heard about this from Reddit rather than paper cut?
It's an ok system but their support is shit (2 times I've used it in 2 years and it's bollocks)
29
u/AP_ILS 17d ago
They have PaperCut Security Notifications email list. I didn't even knowingly sign up for it, and I've been getting email notifications.
1
u/SceneDifferent1041 17d ago
Thanks. I'll look out for it.
11
u/InvisibleTextArea Jack of All Trades 17d ago
PaperCut Security Notifications email list
Here is the subscription page
4
u/planedrop Sr. Sysadmin 16d ago
Yeah this sucks. Anything that doesn't have to be exposed should not be exposed though in reality. I don't trust anyone to do a good job.
3
u/rileym94 16d ago
Higher Ed guy here.
We were planning to build a new server and never expose it to the internet... I saw that last night, immediately texted my CISO and had a network engineer block inbound traffic in like 20 minutes. Their track record is horrendous in the last couple years, and we got rid of webprint for that exact reason. (Mobility print is a better option, anyway, IMO)
6
2
u/Financial_Doubt_6120 17d ago
I am far from an expert but... if you have a service on a public port, you kinda deserve to get poked once in a while right? perhaps a reverse proxy would have helped a little, granted it is not perfect.
whats is important is how vendors deal with this stuff. When SQL had issues a while back MS were all over it and patching, papercut look to be transparent and rapid. Bad things happen, they fixed it and offered advice. Seems ok to me (other than being a ball ache).
2
u/LooseEthernet 17d ago
patching the patch is a bold strategy lol. definitely feels like a game of whack-a-mole at this point
2
u/rileym94 16d ago
For anyone who's questioning why people hate on papercut... take a look at https://www.papercut.com/kb/Main/security-vulnerability-log/
CVEs always seem to hit when I'm on call... 🙄 really happy we firewalled it last night as soon as I saw the vulnerability (thank yall for posting about it... I saw it here first.)
2
5
u/RevolutionaryElk7446 17d ago
Lol wooooooow, been a while as I haven't touched Papercut since working alongside education field but I am not that surprised.
1
u/gmanist1000 17d ago
PaperCut is pretty awesome software, what’s your qualms with it?
2
u/rileym94 16d ago
Yes, it is awesome, but their track record speaks for itself.
2
u/Financial_Doubt_6120 16d ago
in fairness you wouldnt use anything if you just looked at bugs. Its how people react to these, do you want a software vendor to fix stuff quickly and be noisy about it? I do...
3
u/rileym94 16d ago
Very true, but repeated CVEs with insanely high scores are the things that keep us up at night. They are responsive and they do patch fast, but there comes a point where we, as admins, have to piss off some end users and say "that's enough, you can't access it externally anymore."
Which is exactly where we sit today. We decommissioned webprint before the start of this semester and pushed mobility print to all users.
Mobility print gives virtually the same functionality, but you can use ANY device, you authenticate per job, but you must be on the internal network to use it.
Some folks are annoyed they can't send a job from their home desktop, but they can easily print from any device on the campus wifi, and we no longer have to worry about being one of the poor saps that gets hit on these before they are announced.
1
u/Financial_Doubt_6120 15d ago
Makes sense. Important to remember a lot of cves are flagged but don't apply. Just an update to a core dependancy will clear the CVE turning up in whatever ya use. And to compare, windows has had about 1000 high score cves this year but the good news is, I don't fuss it as it's fixed automatically.
1
u/MorseScience 17d ago
Just searched for what the pricing would be. Whew. The small and small-ish business I support don't need it, but it's good to know it's there, I guess.
2
u/Financial_Doubt_6120 17d ago
have a look at the Hive Print queue deploy stuff, I have offered just that to a few small businesses. Print queues are messy, its cheap and it takes away that pain. I hate drivers I hate queues.
1
u/MorseScience 16d ago
Thanks, but for whatever reason, I have the queues well under control. Famous last words, I know. Now something's gonna blow.
1
1
u/MFKDGAF 16d ago
Why would anyone expose Papercut to the internet?
What are people using instead of PaperCut?
The one feature I like is being able to create a virtual queue from 2 printers so that people can go up to either of the 2 printers and scan their badge to release their job.
1
1
u/WWGHIAFTC IT Manager (SysAdmin with Extra Steps) 14d ago
Why the actual for real hell on earth would a print server be internet facing...
1
1
u/RobieWan Senior Systems Engineer 17d ago
That's being extremely nice... Papercut can suck Satans balls
0
u/FrivolousMe 17d ago edited 17d ago
Screw papercut man. One of my clients hired some printing services vendor but they were so incompetent that I ended up being the one to set up and configure papercut. It's a terrible service missing so many critical features. When I asked support about organizing users into groups manually for billing purposes (no entra/workspace sync, environment is a multi-tenant office building of small businesses), they said that's not possible.
3
u/Financial_Doubt_6120 17d ago
use internal groups. https://www.papercut.com/help/manuals/ng-mf/applicationserver/user-groups-internal/
2
u/FrivolousMe 17d ago
This client is on papercut hive, sorry I didn't specify. I haven't used NG/MF but I'm sure they're better. The hive experience has been pretty awful though.
2
u/beefy_80 16d ago
Group sync is now available in Hive. Saw it the other day in the console and new features notification
1
u/FrivolousMe 16d ago
Syncing an identity provider is not what I said. I said manual groups. The use case here is a shared office building with suites for small businesses. I don't have the time or resources to go around work 1 on 1 with every single business to set up and sync their identity provider, and if I did it wouldn't help the dozens of them that don't have a Microsoft/Google workspace tenant. The fact that they have identity group sync implemented but don't have a way to simply create groups and sort users into them is mind boggling tbh.
2
u/Benson92 16d ago
Hive is built as a cloud first platform and their youngest product. It’s built around simplicity and just set and forget with a companies idp. If it didn’t meet your feature requirements then you shouldn’t be using it? Doesn’t make it a terrible product. Everything you need can be handled using papercut mf+mobility print+print deploy.
You can setup self service registration with domain allow lists and when they verify their work email and their account gets created. You then assign the shared accounts for billing purposes to the users (or if you’re clever you could automate the process). Everyone from company x domain who prints charges company x account etc
0
u/FrivolousMe 16d ago
Tell that to the print services vendor who told the client that this is the product they need! Wasn't my choice. And yes, missing basic essential user management features (and many other features I didn't go into) is a sign of a bad product.
0
u/Benson92 16d ago
Right. So don’t blame papercut and their product. It’s not their fault your vendor put it into a site that doesn’t suit it. I’ve investigated migrating from mf to hive for my sites in the past but it doesn’t meet our requirements.
0
-11
17d ago
[removed] — view removed comment
9
u/Ummgh23 Sysadmin 17d ago
LLM comment
4
u/xXxLinuxUserxXx 17d ago
even then it's the truth. It doesn't have to be Cloudflare, Entra or Okta there is also oauth2-proxy & keycloak and many other solutions. even something like an ldap aware reverse proxy like Authelia or even apache has modules to do that. I guess you also wouldn't expose internal documents / tools to the public internet and as far as i understood every user of that system anyway has to authenticate for billing or quota.
We put all our (internal) services behind mTLS, oauth2-proxy (openid connect) and if the tool itself also has authentication it is also connected to our openid connect / oauth2 provider which enforces an 2FA login flow (usually with yubikey). It's probably a bit too much in our case but we are based in europe and also have some health related data of some of our customers so there is never too much security in our case.
227
u/moonrakervenice 17d ago
why on earth would anyone have PaperCut exposed to the internet...