Argument Injection Vulnerability in CUPS Affects OpenPrinting Managers
CVE-2026-105326
2.5LOW
What is CVE-2026-105326?
An argument injection vulnerability exists in CUPS related to email notification handling. The CUPS scheduler processes printer subscription requests that include a mailto notify-recipient-uri. This vulnerability allows a remote attacker to manipulate the recipient address passed to the sendmail program by including a crafted value beginning with a dash (-). If successfully exploited, the attacker can influence the behavior of sendmail, potentially enabling unauthorized execution of commands with the privileges of the CUPS service user, contingent on the configuration of the mail transfer agent and network access to the CUPS service.