CVE-2026-87876

Published: September 11, 2026Last modified: September 11, 2026

Description

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.

Severity score breakdown

ParameterValue
Base score3
Attack VectorADJACENT_NETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScupsUnknown (2.4.2-r2)
25 LTScupsUnknown (2.4.11-r1)
StreamcupsUnknown (2.4.2-r5)

References

ON THIS PAGE