Skip to content
Local Privilege Escalation Vulnerability in CUPS 2.4.16

Local Privilege Escalation Vulnerability in CUPS 2.4.16

First seen 27 Sep 2026, 11:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •CUPS version 2.4.16 is vulnerable to local privilege escalation.
  • •Exploitation involves capturing a Local authentication token via IPP requests.
  • •CUPS 2.4.17 and later versions have been patched.

A local privilege escalation vulnerability has been identified in CUPS version 2.4.16, allowing unprivileged users to gain root access. The exploit involves capturing a Local authentication token through a crafted IPP request to a rogue CUPS server. This vulnerability affects systems running CUPS 2.4.16 and earlier, with a proof-of-concept (PoC) available for exploitation. The attack method leverages a bypass of the FileDevice policy, enabling arbitrary file writes as root. Users are advised against running the PoC on production systems due to its potential for misuse. CUPS versions 2.4.17 and later have been patched to address this vulnerability. The exploit is race-dependent, meaning success is not guaranteed on every attempt. The vulnerability has been reported by multiple sources, indicating a broader awareness within the cybersecurity community.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CUPS vulnerability disclosed
A local privilege escalation vulnerability in CUPS 2.4.16 was publicly disclosed, affecting systems that use this version.
Sploitus
2026-09-27
Proof-of-concept released
A proof-of-concept exploit was released, demonstrating the vulnerability against an existing CUPS installation.
Sploitus
2026-09-27
Patch released for CUPS
CUPS version 2.4.17 was released to address the vulnerability, urging users to upgrade.
Sploitus

More articles in this cluster (2)