CVE-2026-34990Disclosure(openprinting / cups)

LOWCVSS 5.0 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openprinting cups systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cups

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 12 signals
  • Disclosure: 10 classified signals
  • Peaked 4d ago at 6 mentions (2026-04-07); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Products
cups

Deep dive

Activity timeline13 mentions / 7d
02356Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-04-07: 6Mentions · 2026-04-08: 2Mentions · 2026-04-10: 1Mentions · 2026-04-15: 1Mentions · 2026-10-03: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-04-10: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 6Technical Details · 2026-04-08: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-15: 104-0404-0604-0704-0804-1004-1510-03
Signal classification2 categories
Disclosure
1083.3%
PoC
216.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-041
Disclosure1
2026-04-061
PoC1
2026-04-076
Disclosure6
2026-04-082
Disclosure2
2026-04-101
PoC1
2026-04-151
Disclosure1
Full discourse13 posts
  • Simone Margaritelli@evilsocket
    Disclosure

    Two new vulnerabilities have been found in CUPS, CVE-2026-34980 and CVE-2026-34990, which chained together lead to a preauth RCE as root if shared queues are enabled. https://heyitsas.im/posts/cups/ Beautiful research by Asim Viladi Oglu Manizada https://t.co/KqRpyfIfUe

    Post summary

    Two new chained vulnerabilities (CVE‑2026‑34980 & CVE‑2026‑34990) in CUPS allow pre‑authentication remote code execution as root when shared queues are enabled, as reported by Asim Viladi Oglu Manizada.

    24731777319.5K
    47.9K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    7+ CVEs in CUPS https://www.openwall.com/lists/oss-security/2026/04/08/2 The unauth’d RCE as lp (CVE-2026-34980) requires the CUPS server to be reachable over the network and expose a shared PostScript queue. A deliberate config choice. The LPE to root file (over)write (CVE-2026-34990) works on stock config.

    Post summary

    The article announces seven+ CVEs in CUPS, describing an unauthenticated RCE and a local privilege escalation, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0611352.5K
    4.6K followersView on X
  • Cyber Kendra@cyberkendra
    Disclosure

    Linux's Print System Has a Zero-Click Root Hole — and No Fix Yet Two new CUPS flaws (CVE-2026-34980 & CVE-2026-34990) chain into unauthenticated remote-to-root on Linux. No patch yet. Here's what you need to know. https://www.cyberkendra.com/2026/04/linuxs-print-system-has-zero-click-root.html #linux #security #infosec https://t.co/4e1jl57trL

    Post summary

    Two new CUPS vulnerabilities (CVE‑2026‑34980 & CVE‑2026‑34990) enable unauthenticated remote root access on Linux, with no patch available as of now.

    11020154
    1.5K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Unauthenticated RCE-to-root chain discovered in CUPS via CVE-2026-34980 and CVE-2026-34990 — attackers can submit malicious print jobs to gain lp code execution, steal local admin token, create file:// printer, and overwrite root files like /etc/sudoers for full system compromise. https://heyitsas.im/posts/cups/

    Post summary

    A newly disclosed unauthenticated RCE-to-root chain in CUPS (CVE‑2026‑34980/34990) allows attackers to execute code and overwrite /etc/sudoers, enabling full system compromise.

    00012125
    2.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Linux/UNIX の CUPS 脆弱性 CVE-2026-34980/34990:root 権限でのリモートコード実行の恐れ https://iototsecnews.jp/2026/04/07/cups-vulnerabilities-could-allow-remote-attackers-to-achieve-root-level-code-execution/ この CUPS の脆弱性は、システムの基盤となるソフトウェアに潜む、根深い問題を示しています。 CVE-2026-34980 の主な原因は、プリント・ジョブを受け取る際の入力値チェックの不備にあります。本来は除去すべき改行文字が適切に処理されず、設定ファイルへと不正なコマンドが注入されてしまいます。また CVE-2026-34990 では、一時的な検証プロセスや権限情報の受け渡しにおける設計上の隙を突かれ、タイミングの差を利用した競合状態が引き起こされてしまいます。ご利用のチームは、ご注意ください。 #CUPS #CVE202634980 #CVE202634990 #Linux #Unix #Vulnerability

    Post summary

    The article reports two CUPS CVEs (CVE‑2026‑34980 and CVE‑2026‑34990) that could give attackers root‑level remote code execution via input validation misuse and race conditions, but provides no PoC, exploit code, or patch details.

    01000106
    484 followersView on X
  • Syed Aquib@syedaquib77
    PoC

    ⚠️ **Vulnerability Alert:** CUPS remote code execution and root file-overwrite chain (CVE-2026-34980, CVE-2026-34990) 📅 **Timeline:** Disclosure: 2026-04-03, Patch: not released 🆔 **CVE-2026-34980** | 📊 CVSS: 6.1 (🟡 Medium) | 📈 EPSS: 11.42% 🆔 **CVE-2026-34990** | 📊 CVSS: 7.8 (🟠 High) | 📈 EPSS: 1.93% 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** CUPS 2.4.16 🔧 **Fixed Versions:** Public commits with fixes available in OpenPrinting/cups (no released patched version at time of publication) 🫨 **Attack Vectors:** - CVE-2026-34980: Network/adjacent — unauthenticated Print-Job to a shared PostScript queue allowing injection of a malicious PPD entry and execution as lp - CVE-2026-34990: Local — unprivileged user coerces cupsd to authenticate to attacker-controlled localhost IPP using a reusable Authorization: Local token enabling persistent file:/// queue and arbitrary root file overwrite - Chaining: Remote unauthenticated access (CVE-2026-34980) + local token abuse (CVE-2026-34990) => remote, unauthenticated root file overwrite on networked/shared-queue deployments 📝 **Summary:** Two CUPS flaws allow an attacker to achieve code execution as the printing user (CVE-2026-34980) and a local low-privilege user to overwrite root files via a coerced cupsd authentication token (CVE-2026-34990). Chaining the issues yields remote, unauthenticated root file overwrite (PoC shows dropping a sudoers fragment and running commands as root). 📈 **Impact Scope:** Networked/shared-queue CUPS servers running 2.4.16 and prior; potential full system compromise, persistence, and privilege escalation to root when chained. 🛡️ **Recommended Actions:** - Block or restrict TCP/631 (CUPS/IPP) to trusted hosts immediately - Disable anonymous/guest printing and shared PostScript queues until patched - Apply public fixes from OpenPrinting/cups or vendor patches when available - Monitor CUPS logs for unexpected print jobs/queue creation and treat exposed hosts as compromised 🪢 **Related Resources:** - https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf - https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp 🏷 **Tags:** #Cybersecurity #CUPS #RCE

    Post summary

    The alert reports two coordinated CUPS weaknesses, provides technical details and a proof‑of‑concept demonstrating root‑level file overwrite, and urges immediate mitigations, but does not mention active exploitation or a specific exploit tool.

    0000152
    273 followersView on X
  • MA@AstroKrypTech

    I just published CVE-2026–34990 in CUPS https://medium.com/@AstroKrypTech/cve-2026-34990-in-cups-67255a9ff3e6/share/AstroKrypTech?source=social.tw

    0000048
    538 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #CUPS: disponibili #PoC per lo sfruttamento delle vulnerabilità CVE-2026-34980 e CVE-2026-34990 Rischio: 🔴 Tipologia 🔸Remote Code Execution 🔸Privilege Escalation 🔗https://www.acn.gov.it/portale/w/cups-disponibili-poc-per-lo-sfruttamento-di-due-vulnerabilita ⚠️ Mitigazioni disponibili https://t.co/rXqkfXzRvt

    Post summary

    Proof‑of‑Concept code for CVE‑2026‑34980 and CVE‑2026‑34990 is available, with mitigations documented; no evidence of current exploitation is reported.

    0000058
    605 followersView on X
  • Vito Botta@vitobotta
    Disclosure

    That SpaceX researcher using AI agents to find CUPS vulnerabilities is quite interesting. He didn't just prompt "find me an RCE" - he split the problem into "find remote code execution" and "find a root primitive for priv esc". The agents found CVE-2026-34980 (RCE as lp user) and CVE-2026-34990 (root file overwrite), which chain together for full remote compromise. This indeed seems the future of vulnerability research right now: humans setting strategy, with AI agents doing the actual discovery work.

    Post summary

    AI researchers discovered two new CUPS vulnerabilities, CVE-2026-34980 (RCE as lp user) and CVE-2026-34990 (root file overwrite), highlighting potential for full remote compromise, but no exploit or patch information is provided.

    00000118
    922 followersView on X
  • Jared Folkins ✞@JF0LKINS
    Disclosure

    Life comes at you fast! https://heyitsas.im/posts/cups/ “TLDR: my self-orchestrating team of vulnerability hunting agents discovered two issues in CUPS, CVE-2026-34980 and CVE-2026-34990, chainable into unauthenticated remote attacker -> unprivileged RCE -> root file (over)write.”

    Post summary

    The post announces the discovery of two new CUPS CVEs that, when chained, allow unauthenticated attackers to gain unprivileged remote code execution and ultimately overwrite root‑level files.

    00000198
    1.6K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Two chained vulnerabilities in CUPS (CVE-2026-34980, CVE-2026-34990) enable unauthenticated remote code execution and root file overwrite on network-exposed print servers, impacting CUPS 2.4.16 deployments with shared PostScript queues. https://www.theregister.com/2026/04/06/ai_agents_cups_server_rce/

    Post summary

    The article announces two chained vulnerabilities (CVE‑2026‑34980 and CVE‑2026‑34990) in CUPS 2.4.16 that allow unauthenticated RCE and root file overwrite on network‑exposed print servers, but provides no PoC, exploit, or patch information.

    00000102
    2.0K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical CUPS flaws CVE-2026-34980 and CVE-2026-34990 enable unauthenticated RCE and root file overwrite on networked print servers, no official patch released. https://threatcluster.io/cluster/critical-rce-and-root-access-vulnerabilities-discovered-in-c-d1195c3f

    Post summary

    Critical CUPS print server vulnerabilities (CVE-2026-34980 and CVE-2026-34990) have been disclosed, allowing unauthenticated remote code execution and root file overwrite, with no patch available yet.

    0000089
    133 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34990 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to a... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34990

    Post summary

    The post announces CVE‑2026‑34990, describing a local unprivileged user being able to coerce the CUPS daemon into authenticating, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000085
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenprintingcups---

Explore more