Latest releases
CVSS 9.3 CVE-2026-89082 Archive extraction to SYSTEM execution

Independent MFP security research

Where the paper path becomes an attack path.

Independent security research into multifunction printers and the software that connects them to enterprise networks. Print, scan, and document workflows.

PRINT OVERRUN / RESEARCH LAB
Service-manual diagram showing a sheet leaving the expected paper path and crossing a security boundary to become a CVE document.
FIG. 01 / ABNORMAL FEEDBoundary crossed ↗
THE RESEARCH SURFACE

MFPs & fleet software Print & scan Document workflows

Follow the paper path

01 / The findings

Published disclosures

Security findings across the MFP ecosystem. Reported to the vendor first, with the impact, timeline, and available fixes documented.

02 / Behind the research

The workstation is secure.
The paper is in your hands.
What happened in between?

A confidential document leaves a managed workstation. You authenticate at the MFP, collect the pages, and walk away. It feels like a closed loop.

Depending on the setup, that job may have passed through a spooler, a print server, a release queue, and storage on the device. A scan can take another route through email, network shares, or a cloud connector. Each step brings its own software, permissions, and trust.

Holding the printout does not prove that no copy remains elsewhere. A successful scan does not tell you who else could reach the workflow. A flaw along that path can expose documents or turn a service account into access beyond the MFP.

Print Overrun investigates those gaps: where documents go, what the services can do, and whether the controls hold up when someone asks the wrong questions.

About the researcher