CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User
ID: 8c76457e-d9de-5c92-b630-2dabfc8b3c83
STIX ID: report--8c76457e-d9de-5c92-b630-2dabfc8b3c83
Feed Name: cybersecurityNews.com
A critical two-stage zero-day chain in CUPS (affecting versions 2.4.16 and older) allows an attacker to bypass authentication by sending a crafted print job to a shared PostScript queue (CVE-2026-34980), achieve remote code execution as the unprivileged "lp" user, then escalate to root by abusing CUPS' temporary printer creation and a race condition to overwrite arbitrary files (CVE-2026-34990); no official patches were available as of early April 2026 and mitigations include disabling shared legacy queues, restricting network exposure, enforcing authentication, and using MAC controls like AppArmor/SELinux.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
