CVE-2026-34978 is a path traversal vulnerability affecting OpenPrinting CUPS versions 2.4.16 and prior, allowing a remote IPP client to write RSS XML bytes outside the designated cache directory. Rated Medium (CVSS 6.5), this unauthenticated, low-complexity flaw enables a network attacker to overwrite critical CUPS state files by manipulating the notify-recipient-uri. Successful exploitation can lead to a denial of service, causing the CUPS scheduler to fail and previously queued jobs to disappear upon service restart. There are no publicly available patches or known exploit code, and the vulnerability currently shows minimal community discussion or media coverage, suggesting a low immediate exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.16CPE matchmatch criteria | cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.