Local Privilege Escalation in OpenPrinting CUPS by Unprivileged Users
CVE-2026-34990
Key Information:
- Vendor
Openprinting
- Status
- Vendor
- CVE Published:
- 3 April 2026
Badges
What is CVE-2026-34990?
OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on localhost. By utilizing a reusable Authorization token, the attacker can execute administrative requests undetected. Coupled with the ability to create local printers and manipulate the FileDevice policy, an attacker can create persistent file queues that facilitate arbitrary root file overwrites, potentially allowing for command execution with root privileges. No patches are currently available for this vulnerability.
Affected Version(s)
cups <= 2.4.16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
