CVE 5.9 MEDIUM

PaperCut Hive (Ricoh): Plain text password in logs_CVE-2026-7824

5.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files.



An attacker with administrative access to the PaperCut Hive management portal could remotely enable deep logging and subsequently retrieve sensitive device passwords from the logs after an authorized user authenticates at the device. This exposure allows for the lateral movement or unauthorized configuration of the physical print hardware.

Basic Information

ID CVE-2026-7824
Source PaperCut
Published May 5, 2026 at 06:22

Affected Product

Vendor PaperCut
Product PaperCut Hive
Affected Versions PaperCut PaperCut Hive 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.