Zero Day Initiative discloses two PAPPL buffer overflows: unauthenticated RCE rated CVSS 9.8 and local privilege escalation rated CVSS 7.8
On 2026-09-10, the Zero Day Initiative published two advisories for PAPPL, the open-source printer application framework: ZDI-26-656, an unauthenticated heap-based buffer overflow in job processing allowing remote code execution (CVSS 9.8), and ZDI-26-655, a…
The Zero Day Initiative published two PAPPL advisories dated 2026-09-10. ZDI-26-656 covers a heap-based buffer overflow in PAPPL job processing that allows remote attackers to execute arbitrary code with no authentication required; ZDI assigned it a CVSS 9.8 rating. ZDI-26-655 covers a stack-based buffer overflow in PAPPL printer IPP processing that allows local attackers to escalate privileges after obtaining low-privileged code execution; ZDI assigned it a CVSS 7.8 rating. Both disclosures were coordinated by the Zero Day Initiative. Per the advisory text, no CVE identifier was listed for either vulnerability. The reports did not state affected PAPPL versions, patch availability, or whether the flaws have been exploited in the wild.
- ZDI-26-656 (published 2026-09-10): heap-based buffer overflow in PAPPL job processing enables unauthenticated remote code execution; rated CVSS 9.8.
- ZDI-26-655 (published 2026-09-10): stack-based buffer overflow in PAPPL printer IPP processing enables local privilege escalation; rated CVSS 7.8.
- ZDI-26-655 requires prior low-privileged code execution before privileges can be escalated; ZDI-26-656 requires no authentication.
- PAPPL is described as an open-source printer application framework.
- No CVE identifier was listed in the advisory text for either vulnerability.
- Both disclosures were coordinated by the Zero Day Initiative.
Coverage timelineoldest first · each row is one article
- · 5d agoZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI Published Advisories· 35
ZDI-26-656: Unauthenticated heap-based buffer overflow in PAPPL job processing allows remote code execution, rated CVSS 9.8.
- · 5d agoZDI-26-655: PAPPL Printer IPP Processing Stack-based Buffer Overflow Local Privilege Escalation Vulnerability
ZDI Published Advisories· 25
ZDI-26-655: Stack-based buffer overflow in PAPPL printer IPP processing enables local privilege escalation, rated CVSS 7.8.