ZeroHour
Story · 1 source · 2 articlesfirst updated ()

Zero Day Initiative discloses two PAPPL buffer overflows: unauthenticated RCE rated CVSS 9.8 and local privilege escalation rated CVSS 7.8

highAdvisoryimportance 35
What's new: Initial merged summary: this is the first story summary, combining two separately published ZDI advisories (ZDI-26-656 and ZDI-26-655) dated 2026-09-10 into one PAPPL vulnerability story. The two advisories describe distinct flaws and do not conflict on any stated fact; the merged account preserves each advisory's specific CVSS score, attack prerequisite, and the absence of listed CVE identifiers.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-10, the Zero Day Initiative published two advisories for PAPPL, the open-source printer application framework: ZDI-26-656, an unauthenticated heap-based buffer overflow in job processing allowing remote code execution (CVSS 9.8), and ZDI-26-655, a…

The Zero Day Initiative published two PAPPL advisories dated 2026-09-10. ZDI-26-656 covers a heap-based buffer overflow in PAPPL job processing that allows remote attackers to execute arbitrary code with no authentication required; ZDI assigned it a CVSS 9.8 rating. ZDI-26-655 covers a stack-based buffer overflow in PAPPL printer IPP processing that allows local attackers to escalate privileges after obtaining low-privileged code execution; ZDI assigned it a CVSS 7.8 rating. Both disclosures were coordinated by the Zero Day Initiative. Per the advisory text, no CVE identifier was listed for either vulnerability. The reports did not state affected PAPPL versions, patch availability, or whether the flaws have been exploited in the wild.

  • ZDI-26-656 (published 2026-09-10): heap-based buffer overflow in PAPPL job processing enables unauthenticated remote code execution; rated CVSS 9.8.
  • ZDI-26-655 (published 2026-09-10): stack-based buffer overflow in PAPPL printer IPP processing enables local privilege escalation; rated CVSS 7.8.
  • ZDI-26-655 requires prior low-privileged code execution before privileges can be escalated; ZDI-26-656 requires no authentication.
  • PAPPL is described as an open-source printer application framework.
  • No CVE identifier was listed in the advisory text for either vulnerability.
  • Both disclosures were coordinated by the Zero Day Initiative.
ProductsPAPPL
OrganizationsZero Day Initiative

Coverage timeline

  1. · 5d ago
    ZDI Published Advisories· 35
    ZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability

    ZDI-26-656: Unauthenticated heap-based buffer overflow in PAPPL job processing allows remote code execution, rated CVSS 9.8.

  2. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-655: PAPPL Printer IPP Processing Stack-based Buffer Overflow Local Privilege Escalation Vulnerability

    ZDI-26-655: Stack-based buffer overflow in PAPPL printer IPP processing enables local privilege escalation, rated CVSS 7.8.