CVE-2026-34978General(openprinting / cups)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cups

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
cups

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-30: 1Technical Details · 2026-04-30: 104-30
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    General

    🖨️ Medium risk, big chaos: CVE-2026-34978 lets a rogue IPP client path-traverse and clobber CUPS job.cache. “Not a shell” just means attackers don’t need one. #Windows #Security #CUPS https://windowsforum.com/threads/cve-2026-34978-cups-rss-path-traversal-can-corrupt-job-cache-medium-risk.415865/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CupsVulnerability #Cve202634978 #PrintSecurity #IppRssNotifier https://t.co/2p0Je0VZhc

    Post summary

    The tweet alerts about CVE-2026-34978 as a path‑traversal vulnerability affecting CUPS, but offers no PoC, exploit code, active‑use evidence, or patch information.

    0000016
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprintingcups---

Explore more