CVE-2026-34980Disclosure(openprinting / cups)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openprinting cups systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cups

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 9 classified signals
  • Disclosures: 1 classified signal
  • Peaked 3d ago at 6 mentions (2026-04-07); latest day: 1
  • 11 total mentions across 5 days

Affected systems

Products
cups

Deep dive

Activity timeline11 mentions / 5d
02356Mentions · 2026-04-06: 1Mentions · 2026-04-07: 6Mentions · 2026-04-08: 2Mentions · 2026-04-10: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-10: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 5Technical Details · 2026-04-08: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-15: 104-0604-0704-0804-1004-15
Signal classification3 categories
Disclosure
981.8%
Disclosures
19.1%
PoC
19.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-061
Disclosures1
2026-04-076
Disclosure6
2026-04-082
Disclosure2
2026-04-101
PoC1
2026-04-151
Disclosure1
Full discourse11 posts
  • Simone Margaritelli@evilsocket
    Disclosure

    Two new vulnerabilities have been found in CUPS, CVE-2026-34980 and CVE-2026-34990, which chained together lead to a preauth RCE as root if shared queues are enabled. https://heyitsas.im/posts/cups/ Beautiful research by Asim Viladi Oglu Manizada https://t.co/KqRpyfIfUe

    Post summary

    Researchers discovered two chained vulnerabilities (CVE-2026-34980/34990) in CUPS that allow pre-authentication remote code execution as root when shared queues are enabled.

    24731777319.5K
    47.9K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    7+ CVEs in CUPS https://www.openwall.com/lists/oss-security/2026/04/08/2 The unauth’d RCE as lp (CVE-2026-34980) requires the CUPS server to be reachable over the network and expose a shared PostScript queue. A deliberate config choice. The LPE to root file (over)write (CVE-2026-34990) works on stock config.

    Post summary

    The post announces seven new CVEs in CUPS, detailing an unauthenticated RCE that requires a network‑exposed PostScript queue and a local privilege escalation that works on default settings; no exploit code, patches, or proof of active exploitation are discussed.

    0611352.5K
    4.6K followersView on X
  • Cyber Kendra@cyberkendra
    Disclosure

    Linux's Print System Has a Zero-Click Root Hole — and No Fix Yet Two new CUPS flaws (CVE-2026-34980 & CVE-2026-34990) chain into unauthenticated remote-to-root on Linux. No patch yet. Here's what you need to know. https://www.cyberkendra.com/2026/04/linuxs-print-system-has-zero-click-root.html #linux #security #infosec https://t.co/4e1jl57trL

    Post summary

    The article announces two new CUPS flaws (CVE-2026-34980 & CVE-2026-34990) that allow unauthenticated remote-to-root on Linux, noting that no patch is available yet.

    11020154
    1.5K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Unauthenticated RCE-to-root chain discovered in CUPS via CVE-2026-34980 and CVE-2026-34990 — attackers can submit malicious print jobs to gain lp code execution, steal local admin token, create file:// printer, and overwrite root files like /etc/sudoers for full system compromise. https://heyitsas.im/posts/cups/

    Post summary

    The post details the discovery of an unauthenticated RCE-to-root chain in CUPS, outlining how attackers can abuse the CVEs to gain root access, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    00012125
    2.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Linux/UNIX の CUPS 脆弱性 CVE-2026-34980/34990:root 権限でのリモートコード実行の恐れ https://iototsecnews.jp/2026/04/07/cups-vulnerabilities-could-allow-remote-attackers-to-achieve-root-level-code-execution/ この CUPS の脆弱性は、システムの基盤となるソフトウェアに潜む、根深い問題を示しています。 CVE-2026-34980 の主な原因は、プリント・ジョブを受け取る際の入力値チェックの不備にあります。本来は除去すべき改行文字が適切に処理されず、設定ファイルへと不正なコマンドが注入されてしまいます。また CVE-2026-34990 では、一時的な検証プロセスや権限情報の受け渡しにおける設計上の隙を突かれ、タイミングの差を利用した競合状態が引き起こされてしまいます。ご利用のチームは、ご注意ください。 #CUPS #CVE202634980 #CVE202634990 #Linux #Unix #Vulnerability

    Post summary

    The article announces and explains the technical details of two new CUPS CVEs (CVE-2026-34980/34990) that could enable remote code execution with root privileges on Linux/Unix systems.

    01000106
    484 followersView on X
  • Syed Aquib@syedaquib77
    Disclosures

    ⚠️ **Vulnerability Alert:** CUPS remote code execution and root file-overwrite chain (CVE-2026-34980, CVE-2026-34990) 📅 **Timeline:** Disclosure: 2026-04-03, Patch: not released 🆔 **CVE-2026-34980** | 📊 CVSS: 6.1 (🟡 Medium) | 📈 EPSS: 11.42% 🆔 **CVE-2026-34990** | 📊 CVSS: 7.8 (🟠 High) | 📈 EPSS: 1.93% 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** CUPS 2.4.16 🔧 **Fixed Versions:** Public commits with fixes available in OpenPrinting/cups (no released patched version at time of publication) 🫨 **Attack Vectors:** - CVE-2026-34980: Network/adjacent — unauthenticated Print-Job to a shared PostScript queue allowing injection of a malicious PPD entry and execution as lp - CVE-2026-34990: Local — unprivileged user coerces cupsd to authenticate to attacker-controlled localhost IPP using a reusable Authorization: Local token enabling persistent file:/// queue and arbitrary root file overwrite - Chaining: Remote unauthenticated access (CVE-2026-34980) + local token abuse (CVE-2026-34990) => remote, unauthenticated root file overwrite on networked/shared-queue deployments 📝 **Summary:** Two CUPS flaws allow an attacker to achieve code execution as the printing user (CVE-2026-34980) and a local low-privilege user to overwrite root files via a coerced cupsd authentication token (CVE-2026-34990). Chaining the issues yields remote, unauthenticated root file overwrite (PoC shows dropping a sudoers fragment and running commands as root). 📈 **Impact Scope:** Networked/shared-queue CUPS servers running 2.4.16 and prior; potential full system compromise, persistence, and privilege escalation to root when chained. 🛡️ **Recommended Actions:** - Block or restrict TCP/631 (CUPS/IPP) to trusted hosts immediately - Disable anonymous/guest printing and shared PostScript queues until patched - Apply public fixes from OpenPrinting/cups or vendor patches when available - Monitor CUPS logs for unexpected print jobs/queue creation and treat exposed hosts as compromised 🪢 **Related Resources:** - https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf - https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp 🏷 **Tags:** #Cybersecurity #CUPS #RCE

    Post summary

    The alert reports two new CUPS vulnerabilities (CVE-2026-34980, CVE-2026-34990) with Medium/High CVSS scores and provides technical details, PoC evidence, and remediation steps, but no evidence of active exploitation or false positives.

    0000152
    273 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #CUPS: disponibili #PoC per lo sfruttamento delle vulnerabilità CVE-2026-34980 e CVE-2026-34990 Rischio: 🔴 Tipologia 🔸Remote Code Execution 🔸Privilege Escalation 🔗https://www.acn.gov.it/portale/w/cups-disponibili-poc-per-lo-sfruttamento-di-due-vulnerabilita ⚠️ Mitigazioni disponibili https://t.co/rXqkfXzRvt

    Post summary

    The post announces that PoCs for CVE-2026-34980 and CVE-2026-34990 are available, highlights RCE and privilege‑escalation risks, and points to available mitigations.

    0000058
    605 followersView on X
  • Vito Botta@vitobotta
    Disclosure

    That SpaceX researcher using AI agents to find CUPS vulnerabilities is quite interesting. He didn't just prompt "find me an RCE" - he split the problem into "find remote code execution" and "find a root primitive for priv esc". The agents found CVE-2026-34980 (RCE as lp user) and CVE-2026-34990 (root file overwrite), which chain together for full remote compromise. This indeed seems the future of vulnerability research right now: humans setting strategy, with AI agents doing the actual discovery work.

    Post summary

    A SpaceX researcher leveraged AI agents to identify two new CUPS CVEs—CVE‑2026‑34980 (remote code execution as lp user) and CVE‑2026‑34990 (root file overwrite)—that can be chained for full remote compromise.

    00000118
    922 followersView on X
  • Jared Folkins ✞@JF0LKINS
    Disclosure

    Life comes at you fast! https://heyitsas.im/posts/cups/ “TLDR: my self-orchestrating team of vulnerability hunting agents discovered two issues in CUPS, CVE-2026-34980 and CVE-2026-34990, chainable into unauthenticated remote attacker -> unprivileged RCE -> root file (over)write.”

    Post summary

    The post announces two newly discovered CUPS CVEs that chain into an unprivileged RCE leading to root file overwrite; no PoC, exploit code, patch, or active exploitation is reported.

    00000198
    1.6K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Two chained vulnerabilities in CUPS (CVE-2026-34980, CVE-2026-34990) enable unauthenticated remote code execution and root file overwrite on network-exposed print servers, impacting CUPS 2.4.16 deployments with shared PostScript queues. https://www.theregister.com/2026/04/06/ai_agents_cups_server_rce/

    Post summary

    Two newly disclosed CUPS vulnerabilities allow unauthenticated remote code execution and root file overwrite on network‑exposed print servers, affecting CUPS 2.4.16 deployments with shared PostScript queues.

    00000102
    2.0K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical CUPS flaws CVE-2026-34980 and CVE-2026-34990 enable unauthenticated RCE and root file overwrite on networked print servers, no official patch released. https://threatcluster.io/cluster/critical-rce-and-root-access-vulnerabilities-discovered-in-c-d1195c3f

    Post summary

    The message reports newly discovered critical CUPS vulnerabilities (CVE-2026-34980/34990) that allow unauthenticated RCE and root file overwrite, with no patch yet available.

    0000089
    133 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprintingcups---

Explore more