Privilege Escalation Vulnerability in CUPS via Privileged Serial Backend
CVE-2026-95511

8.2HIGH

What is CVE-2026-95511?

A privilege escalation vulnerability exists in the Common Unix Printing System (CUPS) when utilized with the cups-filters serial backend. Local users who are part of the lpadmin group can configure printers that rely on a privileged serial backend. The CUPS scheduler is unable to properly restrict the path component of non-file device URIs. As a result, the root-privileged backend may inadvertently allow attackers to write malicious print data to arbitrary files. This could lead to modifications of security-sensitive CUPS configurations, potentially enabling the execution of root-level code. To exploit this vulnerability, an attacker must possess local membership in the lpadmin group and have a serial backend binary installed with root-only permissions.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.