CVE-2026-34990

Name
CVE-2026-34990
Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* cups >= None <= 2.4.16

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cups edge-main 2.4.18-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
cups edge-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.13-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.10-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.3-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r7 None possibly vulnerable
cups edge-main 2.4.2-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.3.3-r0 None possibly vulnerable
cups edge-main 2.2.12-r0 None possibly vulnerable
cups edge-main 2.2.10-r0 None possibly vulnerable
cups 3.23-main 2.4.18-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
cups 3.23-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.23-main 2.4.13-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.22-main 2.4.18-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
cups 3.22-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.22-main 2.4.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.22-main 2.4.10-r1 None possibly vulnerable
cups 3.22-main 2.4.9-r0 None possibly vulnerable
cups 3.22-main 2.4.7-r0 None possibly vulnerable
cups 3.22-main 2.4.2-r7 None possibly vulnerable
cups 3.22-main 2.4.2-r0 None possibly vulnerable
cups 3.22-main 2.3.3-r0 None possibly vulnerable
cups 3.22-main 2.2.12-r0 None possibly vulnerable
cups 3.22-main 2.2.10-r0 None possibly vulnerable
cups 3.21-main 2.4.18-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
cups 3.21-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.21-main 2.4.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.21-main 2.4.10-r1 None possibly vulnerable
cups 3.21-main 2.4.9-r0 None possibly vulnerable
cups 3.21-main 2.4.7-r0 None possibly vulnerable
cups 3.21-main 2.4.2-r7 None possibly vulnerable
cups 3.21-main 2.4.2-r0 None possibly vulnerable
cups 3.21-main 2.3.3-r0 None possibly vulnerable
cups 3.21-main 2.2.12-r0 None possibly vulnerable
cups 3.21-main 2.2.10-r0 None possibly vulnerable
cups 3.20-main 2.4.18-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
cups 3.20-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.9-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.7-r0 None possibly vulnerable
cups 3.20-main 2.4.2-r7 None possibly vulnerable
cups 3.20-main 2.4.2-r0 None possibly vulnerable
cups 3.20-main 2.3.3-r0 None possibly vulnerable
cups 3.20-main 2.2.12-r0 None possibly vulnerable
cups 3.20-main 2.2.10-r0 None possibly vulnerable
cups 3.19-main 2.4.9-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.19-main 2.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.19-main 2.4.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.19-main 2.4.2-r7 None possibly vulnerable
cups 3.19-main 2.4.2-r0 None possibly vulnerable
cups 3.19-main 2.3.3-r0 None possibly vulnerable
cups 3.19-main 2.2.12-r0 None possibly vulnerable
cups 3.19-main 2.2.10-r0 None possibly vulnerable