Critical Vulnerabilities in PAPPL Printer Software Uncovered
Article Content
Two critical vulnerabilities have been identified in PAPPL printer software, affecting installations that handle IPP and job processing. The first vulnerability (ZDI-26-655) allows local attackers to escalate privileges by exploiting a flaw in printer attribute handling, requiring low-privileged code execution. The second vulnerability (ZDI-26-656) enables remote attackers to execute arbitrary code without authentication by exploiting improper validation in raster document parsing. Both vulnerabilities can lead to significant security breaches, with the potential for arbitrary code execution in the context of the service account or root. PAPPL has issued updates to address these vulnerabilities. The vulnerabilities were reported to the vendor on August 4, 2026, and advisories were publicly released on September 10, 2026.
Key Points: • Two critical vulnerabilities in PAPPL software allow privilege escalation and remote code execution. • Local attackers can exploit ZDI-26-655, while ZDI-26-656 allows remote exploitation without authentication. • PAPPL has released updates to mitigate these vulnerabilities as of September 10, 2026.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.