CVE-2026-34980

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) OpenPrinting CUPS es un sistema de impresión de código abierto para Linux y otros sistemas operativos tipo Unix. En las versiones 2.4.16 y anteriores, en un cupsd expuesto a la red con una cola de destino compartida, un cliente no autorizado puede enviar un trabajo de impresión (Print-Job) a esa cola PostScript compartida sin autenticación. El servidor acepta un valor de page-border suministrado como textWithoutLanguage, conserva un salto de línea incrustado a través del escape de opciones y el reanálisis, y luego reanaliza el texto PPD: resultante de la segunda línea como un registro de control de programador de confianza. Un trabajo de impresión en bruto de seguimiento puede, por lo tanto, hacer que el servidor ejecute un binario existente elegido por el atacante, como /usr/bin/vim como lp. En el momento de la publicación, no hay parches disponibles públicamente.

16 Apr 2026, 18:28

Type Values Removed Values Added
First Time Openprinting cups
Openprinting
CPE cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
References () https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf - () https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

03 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 22:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-34980

Mitre link : CVE-2026-34980

CVE.ORG link : CVE-2026-34980


JSON object : View

Products Affected

openprinting

  • cups
CWE
CWE-20

Improper Input Validation