Argument Injection Vulnerability in CUPS Affects OpenPrinting Managers
CVE-2026-105326

2.5LOW

What is CVE-2026-105326?

An argument injection vulnerability exists in CUPS related to email notification handling. The CUPS scheduler processes printer subscription requests that include a mailto notify-recipient-uri. This vulnerability allows a remote attacker to manipulate the recipient address passed to the sendmail program by including a crafted value beginning with a dash (-). If successfully exploited, the attacker can influence the behavior of sendmail, potentially enabling unauthorized execution of commands with the privileges of the CUPS service user, contingent on the configuration of the mail transfer agent and network access to the CUPS service.

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.