MEDIUM
OpenPrinting
CVE published 2026-04-03
CVE-2026-34978
OpenPrinting CUPS is vulnerable to a path traversal attack in the RSS notifier. Versions 2.4.16 and prior allow a remote IPP client to write RSS XML bytes outside CacheDir/rss. The notifier, running as lp, can replace root-managed state files via temp-file + rename(). This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. System administrators and users of OpenPrinting CUPS should be aware o [truncated]