CVE-2026-34990 affects OpenPrinting CUPS versions 2.4.16 and prior, allowing a local unprivileged user to achieve arbitrary root file overwrite and subsequent root command execution. This is accomplished by coercing cupsd into authenticating to an attacker-controlled IPP service, enabling the creation of a malicious shared printer queue. Rated as Medium severity (CVSS 5.0), exploitation requires local access but no user interaction. While a Proof-of-Concept is mentioned in the description, there are no publicly available exploits, evidence of active exploitation, or significant community discussion at this time. Patches for this vulnerability are not yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.16CPE matchmatch criteria | cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.