CVE-2026-34980 is a remote code execution vulnerability in OpenPrinting CUPS affecting version 2.4.16 and earlier. When cupsd is network-exposed and a shared PostScript queue is available, the default policy can allow unauthenticated clients to submit Print-Job requests to that queue. The flaw arises from improper handling of attacker-controlled job attributes during option escaping and reparsing: a page-border value supplied as textWithoutLanguage can retain an embedded newline, and the reparsed second line is then interpreted as a trusted scheduler control record beginning with PPD:. This allows an attacker to inject malicious PPD content into the queue configuration. A subsequent raw print job can then cause CUPS to execute an attacker-chosen existing binary under the lp account. The issue is effectively an authentication bypass combined with command or configuration injection through trusted PPD processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Более поздняя уязвимость в CUPS, упомянутая как наследник той же архитектурной проблемы; позволяет неаутентифицированному клиенту в той же сети внедрить директиву в PPD через newline-инъекцию в атрибуте page-border.
A CUPS vulnerability that formed part of a chained attack leading to unauthenticated remote code execution and subsequent root file overwrite.
A vulnerability in OpenPrinting CUPS where a shared PostScript queue allows anonymous print-job requests to reach lp code execution over the network.
A zero-day vulnerability in CUPS that allows unauthenticated remote attackers to bypass authentication and achieve remote code execution as the unprivileged "lp" service user via malicious print requests to exposed shared PostScript queues.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.