Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41079

20
FAUCET Score

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.

First published: Apr 24, 2026Last modified: Apr 25, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.17CPE matchmatch criteria
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 51st percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 cups 2.4.16-1 on Azure Linux 3.0Fixed in: 2.4.18-1
microsoftpatch availablevia msrc
Product: 20737-17084Fixed in: 2.4.18-1
ubuntupatch availablevia ubuntu_usn
Product: cups (jammy)Fixed in: 2.4.1op1-1ubuntu4.20
ubuntupatch availablevia ubuntu_usn
Product: cups (resolute)Fixed in: 2.4.16-1ubuntu1.2
ubuntupatch availablevia ubuntu_usn
Product: cups (noble)Fixed in: 2.4.7-1.2ubuntu7.13
ubuntupatch availablevia ubuntu_usn
Product: cups (questing)Fixed in: 2.4.12-0ubuntu3.9

Vendor Advisories (2)

ubuntuUSN-8405-1

CUPS vulnerabilities

Jun 8, 2026
microsoft2026-Apr/CVE-2026-41079Moderate

OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users

Apr 14, 2026

References

github.com / OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080
Patch
github.com / OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737
Patch
github.com / OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv
ExploitMitigationPatchVendor Advisory