Researchers disclosed a high-impact vulnerability chain in OpenPrinting CUPS affecting version 2.4.16 and earlier that can let an unauthenticated remote attacker progress from network-reachable print-job submission to code execution as lp and then to a root-level file overwrite. The chain combines CVE-2026-34980, which abuses anonymous Print-Job requests against a shared PostScript queue, with CVE-2026-34990, an authorization flaw that lets a local unprivileged user coerce cupsd into authenticating to an attacker-controlled localhost IPP service and reuse a print admin token to overwrite root-owned files. Public advisories and proof-of-concept details were released by researcher Asim Viladi Oglu Manizada and OpenPrinting, and fixes were committed publicly even though no patched release was yet available.
Defenders were urged to reduce exposure immediately because exploitation depends on reachable cupsd services, legacy shared queues, and permissive submission behavior rather than user interaction. Recommended mitigations include disabling or restricting network exposure of CUPS, requiring authentication for shared queue submissions, disabling shared legacy queues where possible, and confining the service with SELinux or AppArmor. Follow-on discussion noted that removing CUPS outright may be impractical on some Ubuntu systems because cupsd is commonly installed by default and intertwined with other packages, making service isolation and firewalling more realistic short-term controls.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Follow-up discussion on oss-sec noted that removing CUPS on Ubuntu can be impractical because it is installed by default and may be re-enabled or reinstalled; another reply clarified that the vulnerable component is cupsd rather than libcups and suggested daemon management or firewall isolation.
The Canadian Centre for Cyber Security issued advisory AV26-326, urging administrators to review the OpenPrinting advisories, apply mitigations, and update when fixes become available.
An oss-sec mailing list post disclosed multiple CUPS vulnerabilities, highlighting CVE-2026-34980 and CVE-2026-34990 and recommending mitigations such as limiting network exposure and using confinement controls.
By April 5, public commits containing fixes for the newly disclosed CUPS vulnerabilities had been published, although no fixed CUPS release was yet available.
OpenPrinting published security advisories for multiple CUPS vulnerabilities, including CVE-2026-34980 and CVE-2026-34990, describing an unauthenticated remote-to-root attack chain affecting CUPS 2.4.16 and earlier.
A GitHub security advisory published a proof-of-concept showing how a shared PostScript queue flaw in CUPS 2.4.16 could be exploited to achieve code execution as the lp user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcego.theregister.com
Open sourceseclists.org
Open sourceheyitsas.im
Open sourcegithub.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.