Access Control Bypass Vulnerability in CUPS by OpenPrinting
CVE-2026-87876

3LOW

What is CVE-2026-87876?

A vulnerability in CUPS's scheduler allows for the potential bypass of access controls based on case-insensitive comparisons of request-derived usernames. This issue specifically affects the ACL (Access Control List) validation and private attribute filtering when certain configurations are employed. If exploited, unauthorized users may gain inappropriate access to resources, highlighting the need for immediate patching and configurations adjustments in affected environments.

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank arbor-s (Independent Security Researcher) for reporting this issue.
.