Authentication Bypass vulnerability in the authorization handling of the CUPS print server. The flaw exists in the cupsdAuthorize() function (scheduler/auth.c) where, if the configured AuthType is anything other than Basic, but the request still includes an Authorization: Basic ... header, the password validation step is skipped. This allows an attacker to bypass authentication checks entirely. By exploiting this issue, an attacker can perform privileged operations, including modifying configuration files, without providing valid credentials. This vulnerability can be exploited remotely depending on the deployment configuration and does not require valid authentication.
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
Cupsd Listen arbitrary chmod 0140777
A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.
cups: Remote DoS via null dereference
Last updated 8 June 2026
Last updated 8 June 2026
CUPS has an integer underflow in ppdCreateFromIPP causes root cupsd crash via negative job-password-supported
CUPS has a use-after-free in cupsdDeleteTemporaryPrinters via dangling subscription pointer
Last updated 8 June 2026
A client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients.
Last updated 8 June 2026
Last updated 8 June 2026
Last updated 8 June 2026
A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.
https://heyitsas.im/posts/cups/ discloses: 1. CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach lp code execution over the network
2. CVE-2026-34990: Local print admin token disclosure using temporary printers
At a high level, in the first vulnerability, the attacker:
1. Submits a malicious print job to a shared PostScript queue, 2. Gets CUPS to treat attacker-controlled text as a trusted queue config by abusing a parsing bug, and 3. Gets code execution as the CUPS service user, lp (vim in the PoC)
And in the second vulnerability, the attacker:
1. Uses any unprivileged local user to set up a localhost listener, 2. Creates a local printer object in CUPS, pointing it at the listener above, 3. Gets CUPS to authenticate to it and captures the auth token, 4. Creates another queue pointing at file:///... for the target rootful write, 5. Uses the token to race against CUPS validation logic’s cleanup of the dangerous queue, and 6. Writes what they want into the target file:///... (/etc/sudoers.d/... in the PoC)
any unprivileged local user that can bind on some TCP port and reach the local CUPS listener.
Are you affected? + Mitigation
The unauth’d RCE as lp (CVE-2026-34980) requires the CUPS server to be reachable over the network and expose a shared PostScript queue (these are legacy, but still used). This would be a deliberate config choice – realistic for, say, networked printing servers in your corporate environment, but not for your desktop (unless you for some reason set it up to be a remote printing server).
The LPE to root file (over)write (CVE-2026-34990), on the other hand, works on the stock CUPS config.
For both issues, the harm can be limited by a security module that confines CUPS (e.g., SELinux, AppArmor, etc.). So, if you run CUPS under a sane security policy (default on some distributions), the impact of both As of 4/5/2026, there are public commits with fixes to both issues but no fixed release (latest being 2.4.16). So, your best mitigations are:
Do not expose CUPS over the network with a shared PostScript queue – or at all If you must use a shared queue, require auth for job submissions to that queue Make sure your CUPS runs under a reasonable AppArmor/SELinux/etc. policy, so that the impact is minimized even if you are targeted Further details, including about how the bugs were found and the PoC can be found in the blog post at https://heyitsas.im/posts/cups/ and the article at https://www.theregister.com/2026/04/06/aiagentscupsserverrce/
The CUPS maintainers have published advisories for the above at:
CVE-2026-34980: https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf
CVE-2026-34990: https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp
Additionally, in the past week they've also published advisories for:
CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9
CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr
CVE-2026-34979: Heap overflow in getoptions() https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh
CVE-2026-39314: Integer underflow in ppdCreateFromIPP causes root cupsd crash via negative job-password-supported https://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7
CVE-2026-39316: Use-after-free in cupsdDeleteTemporaryPrinters via dangling subscription pointer https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg
<no CVE>: Out-of-bounds heap read in cupsdSetPrinterAttr marker-types parsing https://github.com/OpenPrinting/cups/security/advisories/GHSA-qfp8-9frx-5j48
-- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/solaris
On 2026-04-08 03:40, Peter Gutmann wrote: Under Ubuntu it's installed by default and deeply embedded into things (some packages can't be removed at all, try a 'sudo apt purge libcups' but whatever you do don't hit 'y') libcups itself is only the client side that does not seem vulnerable to any of the issues, cupsd can be managed like any other daemon, and worst case can be firewalled off if that does not work for whatever reason.
CVE-2026-34980 and CVE-2026-34990