Executive brief
OpenPrinting CUPS is the standard printing system for Linux and Unix-like operating systems. A vulnerability in how it handles local printer creation allows a standard, unprivileged user to trick the system into granting them administrative access. By exploiting this, an attacker can overwrite critical system files, potentially leading to full control of the computer (root access).
Technical details
A vulnerability in OpenPrinting CUPS versions 2.4.16 and prior allows a local unprivileged user to coerce the cupsd daemon into authenticating to an attacker-controlled localhost IPP service. This interaction leaks a reusable 'Authorization: Local' token, which the attacker can then use to authorize administrative requests. By combining the 'CUPS-Create-Local-Printer' operation with 'printer-is-shared=true', an attacker can bypass FileDevice policy restrictions to persist a printer queue pointing to a local file (e.g., file:///etc/sudoers.d/pwn). Printing to this queue causes the scheduler to overwrite the target file with attacker-controlled content as the root user. A patch is available in version 2.4.17.
Affected products
- OpenPrinting CUPS <= 2.4.16
Timeline
- 2026-04-01: advisory: Vendor advisory GHSA-c54j-2vqw-wpwp published.
- 2026-04-03: disclosed: CVE-2026-34990 published.
- 2026-04-01: patched: Fixed in version 2.4.17.