Where
-Infinity
0
Severity
6.1
Input Validation
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Last updated 8 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
4

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.

First published (updated )
Severity
5.5
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients.

1 / 3
Source: Red Hat
First published (updated )
Severity
6.7
Out-of-bounds Read
AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.

1 / 3
Source: Red Hat
First published (updated )
Severity
4

A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.

First published (updated )
Severity
8
AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Authentication Bypass vulnerability in the authorization handling of the CUPS print server. The flaw exists in the cupsdAuthorize() function (scheduler/auth.c) where, if the configured AuthType is anything other than Basic, but the request still includes an Authorization: Basic ... header, the password validation step is skipped. This allows an attacker to bypass authentication checks entirely. By exploiting this issue, an attacker can perform privileged operations, including modifying configuration files, without providing valid credentials. This vulnerability can be exploited remotely depending on the deployment configuration and does not require valid authentication.

1 / 3
Source: Red Hat
First published (updated )
Severity
6.5
Null Pointer Dereference, Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

cups: Remote DoS via null dereference

1 / 3
Source: Microsoft
First published (updated )
Severity
6.3
AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N

Last updated 8 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
5.3
Buffer Overflow
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Last updated 8 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
5
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Last updated 8 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
6.5
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Last updated 8 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
6.2
Integer Underflow
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CUPS has an integer underflow in ppdCreateFromIPP causes root cupsd crash via negative job-password-supported

1 / 3
Source: Microsoft
First published (updated )
Severity
7.7
Use After Free, Race Condition
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Accounts. A privacy issue was addressed with improved private data redaction for log entries.

1 / 15
Source: Apple
First published (updated )
Severity
5.4
Infoleak
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Last updated 8 June 2026

1 / 3
Source: Ubuntu
First published (updated )
Severity
6.2
Use After Free
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CUPS has a use-after-free in cupsdDeleteTemporaryPrinters via dangling subscription pointer

1 / 3
Source: Microsoft
First published (updated )

On 2026-04-08 03:40, Peter Gutmann wrote: Under Ubuntu it's installed by default and deeply embedded into things (some packages can't be removed at all, try a 'sudo apt purge libcups' but whatever you do don't hit 'y') libcups itself is only the client side that does not seem vulnerable to any of the issues, cupsd can be managed like any other daemon, and worst case can be firewalled off if that does not work for whatever reason.

First published (updated )

CVE-2026-34980 and CVE-2026-34990

First published (updated )
Social
reddit

https://heyitsas.im/posts/cups/ discloses: 1. CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach lp code execution over the network

2. CVE-2026-34990: Local print admin token disclosure using temporary printers

At a high level, in the first vulnerability, the attacker:

1. Submits a malicious print job to a shared PostScript queue, 2. Gets CUPS to treat attacker-controlled text as a trusted queue config by abusing a parsing bug, and 3. Gets code execution as the CUPS service user, lp (vim in the PoC)

And in the second vulnerability, the attacker:

1. Uses any unprivileged local user to set up a localhost listener, 2. Creates a local printer object in CUPS, pointing it at the listener above, 3. Gets CUPS to authenticate to it and captures the auth token, 4. Creates another queue pointing at file:///... for the target rootful write, 5. Uses the token to race against CUPS validation logic’s cleanup of the dangerous queue, and 6. Writes what they want into the target file:///... (/etc/sudoers.d/... in the PoC)

any unprivileged local user that can bind on some TCP port and reach the local CUPS listener.

Are you affected? + Mitigation

The unauth’d RCE as lp (CVE-2026-34980) requires the CUPS server to be reachable over the network and expose a shared PostScript queue (these are legacy, but still used). This would be a deliberate config choice – realistic for, say, networked printing servers in your corporate environment, but not for your desktop (unless you for some reason set it up to be a remote printing server).

The LPE to root file (over)write (CVE-2026-34990), on the other hand, works on the stock CUPS config.

For both issues, the harm can be limited by a security module that confines CUPS (e.g., SELinux, AppArmor, etc.). So, if you run CUPS under a sane security policy (default on some distributions), the impact of both As of 4/5/2026, there are public commits with fixes to both issues but no fixed release (latest being 2.4.16). So, your best mitigations are:

Do not expose CUPS over the network with a shared PostScript queue – or at all If you must use a shared queue, require auth for job submissions to that queue Make sure your CUPS runs under a reasonable AppArmor/SELinux/etc. policy, so that the impact is minimized even if you are targeted Further details, including about how the bugs were found and the PoC can be found in the blog post at https://heyitsas.im/posts/cups/ and the article at https://www.theregister.com/2026/04/06/aiagentscupsserverrce/

The CUPS maintainers have published advisories for the above at:

CVE-2026-34980: https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf

CVE-2026-34990: https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp

Additionally, in the past week they've also published advisories for:

CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9

CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr

CVE-2026-34979: Heap overflow in getoptions() https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh

CVE-2026-39314: Integer underflow in ppdCreateFromIPP causes root cupsd crash via negative job-password-supported https://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7

CVE-2026-39316: Use-after-free in cupsdDeleteTemporaryPrinters via dangling subscription pointer https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg

<no CVE>: Out-of-bounds heap read in cupsdSetPrinterAttr marker-types parsing https://github.com/OpenPrinting/cups/security/advisories/GHSA-qfp8-9frx-5j48

-- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/solaris

First published (updated )
Severity
6.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Cupsd Listen arbitrary chmod 0140777

1 / 4
Source: Microsoft
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203