logo

CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User

ID: 8c76457e-d9de-5c92-b630-2dabfc8b3c83

STIX ID: report--8c76457e-d9de-5c92-b630-2dabfc8b3c83

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical two-stage zero-day chain in CUPS (affecting versions 2.4.16 and older) allows an attacker to bypass authentication by sending a crafted print job to a shared PostScript queue (CVE-2026-34980), achieve remote code execution as the unprivileged "lp" user, then escalate to root by abusing CUPS' temporary printer creation and a race condition to overwrite arbitrary files (CVE-2026-34990); no official patches were available as of early April 2026 and mitigations include disabling shared legacy queues, restricting network exposure, enforcing authentication, and using MAC controls like AppArmor/SELinux.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.