Path Traversal Vulnerability in OpenPrinting CUPS Affects Linux and Unix-like Systems
CVE-2026-34978
What is CVE-2026-34978?
The OpenPrinting CUPS system is subject to a path traversal vulnerability up to version 2.4.16. The RSS notifier allows a remote IPP client to exploit the notify-recipient-uri function leading to arbitrary writes outside the designated CacheDir/rss directory. This can allow unauthorized manipulation of files, particularly affecting the cache used by CUPS to manage print jobs. As the CacheDir is typically group-writable, an attacker can replace critical files using mechanisms like temp-file and rename. Consequently, the job cache can be corrupted, resulting in the loss of queued print jobs upon restarting the CUPS daemon. There are currently no public patches available to address this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cups <= 2.4.16
