CVE Explorer
CVE-2026-6645
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference.
Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executabl
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Windows"],"product":"Print Deploy","vendor":"PaperCut","versions":[{"lessThan":"1.10.4178","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:201b5527c7458a0f11646e63509b2989692edb64517047203939b80f6a8e602f · sha256:40776b373d800f46… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":7.3,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:201b5527c7458a0f11646e63509b2989692edb64517047203939b80f6a8e602f · sha256:40776b373d800f46… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-427","description":"CWE-427 Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:201b5527c7458a0f11646e63509b2989692edb64517047203939b80f6a8e602f · sha256:40776b373d800f46… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-june-2026/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:201b5527c7458a0f11646e63509b2989692edb64517047203939b80f6a8e602f · sha256:40776b373d800f46… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.