← Global Threat Landscape
CVE-2023-27350
CWE-284
Critical
103.8
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 99.99%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Apr 2023
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-284
- Published
- 20 Apr 2023
- Last modified 27 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-27350Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time