CVE-2026-34990 is a local privilege escalation vulnerability in OpenPrinting CUPS versions 2.4.16 and prior. A local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. This token allows driving /admin/ requests on localhost. An attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to pe [truncated]
CVE-2026-34980 is a MEDIUM severity vulnerability in OpenPrinting CUPS, a popular open-source printing system for Linux and Unix-like operating systems. In versions 2.4.16 and prior, an unauthorized client can send a Print-Job to a shared PostScript queue without authentication, potentially allowing execution of an attacker-chosen existing binary. This vulnerability exists due to improper handling of page [truncated]
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. A heap-based buffer overflow exists in the CUPS scheduler when building filter option strings from job attributes in versions 2.4.16 and prior. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of OpenPrinting CUPS versions 2.4.16 and prior should be aware of this vulnerability and [truncated]
OpenPrinting CUPS is vulnerable to a path traversal attack in the RSS notifier. Versions 2.4.16 and prior allow a remote IPP client to write RSS XML bytes outside CacheDir/rss. The notifier, running as lp, can replace root-managed state files via temp-file + rename(). This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. System administrators and users of OpenPrinting CUPS should be aware o [truncated]
The OpenPrinting CUPS printing system for Linux and other Unix-like operating systems contains an authorization bypass vulnerability in versions 2.4.16 and prior. The vulnerability is due to case-insensitive username comparison during authorization checks in the CUPS daemon (cupsd). This allows an unprivileged user to gain unauthorized access to restricted operations by using a username that differs only [truncated]