PatchSiren

OpenPrinting CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenPrinting CVE published 2026-04-03

CVE-2026-34990

CVE-2026-34990 is a local privilege escalation vulnerability in OpenPrinting CUPS versions 2.4.16 and prior. A local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. This token allows driving /admin/ requests on localhost. An attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to pe [truncated]

MEDIUM OpenPrinting CVE published 2026-04-03

CVE-2026-34980

CVE-2026-34980 is a MEDIUM severity vulnerability in OpenPrinting CUPS, a popular open-source printing system for Linux and Unix-like operating systems. In versions 2.4.16 and prior, an unauthorized client can send a Print-Job to a shared PostScript queue without authentication, potentially allowing execution of an attacker-chosen existing binary. This vulnerability exists due to improper handling of page [truncated]

MEDIUM OpenPrinting CVE published 2026-04-03

CVE-2026-34979

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. A heap-based buffer overflow exists in the CUPS scheduler when building filter option strings from job attributes in versions 2.4.16 and prior. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of OpenPrinting CUPS versions 2.4.16 and prior should be aware of this vulnerability and [truncated]

MEDIUM OpenPrinting CVE published 2026-04-03

CVE-2026-34978

OpenPrinting CUPS is vulnerable to a path traversal attack in the RSS notifier. Versions 2.4.16 and prior allow a remote IPP client to write RSS XML bytes outside CacheDir/rss. The notifier, running as lp, can replace root-managed state files via temp-file + rename(). This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. System administrators and users of OpenPrinting CUPS should be aware o [truncated]

MEDIUM OpenPrinting CVE published 2026-04-03

CVE-2026-27447

The OpenPrinting CUPS printing system for Linux and other Unix-like operating systems contains an authorization bypass vulnerability in versions 2.4.16 and prior. The vulnerability is due to case-insensitive username comparison during authorization checks in the CUPS daemon (cupsd). This allows an unprivileged user to gain unauthorized access to restricted operations by using a username that differs only [truncated]