Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34990

33
FAUCET Score

CVE-2026-34990 affects OpenPrinting CUPS versions 2.4.16 and prior, allowing a local unprivileged user to achieve arbitrary root file overwrite and subsequent root command execution. This is accomplished by coercing cupsd into authenticating to an attacker-controlled IPP service, enabling the creation of a malicious shared printer queue. Rated as Medium severity (CVSS 5.0), exploitation requires local access but no user interaction. While a Proof-of-Concept is mentioned in the description, there are no publicly available exploits, evidence of active exploitation, or significant community discussion at this time. Patches for this vulnerability are not yet available.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.4.16CPE matchmatch criteria
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.0MEDIUM

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 57th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: 20737-17084Fixed in: 2.4.17-1
microsoftpatch availablevia msrc
Product: azl3 cups 2.4.16-1 on Azure Linux 3.0Fixed in: 2.4.17-1
ubuntupatch availablevia ubuntu_usn
Product: cups (questing)Fixed in: 2.4.12-0ubuntu3.9
ubuntupatch availablevia ubuntu_usn
Product: cups (jammy)Fixed in: 2.4.1op1-1ubuntu4.20
ubuntupatch availablevia ubuntu_usn
Product: cups (resolute)Fixed in: 2.4.16-1ubuntu1.2
ubuntupatch availablevia ubuntu_usn
Product: cups (noble)Fixed in: 2.4.7-1.2ubuntu7.13
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

ubuntuUSN-8405-1

CUPS vulnerabilities

Jun 8, 2026
microsoft2026-Apr/CVE-2026-34990Moderate

OpenPrinting CUPS: Local print admin token disclosure using temporary printers

Apr 2, 2026

References

github.com / OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp
ExploitVendor Advisory