Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87876

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 3
EPSS Низкий

Описание

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.

Меры по смягчению последствий

Fixed on upstream master branch with commit f56844d and for versions 2.4.x with commit 88e67c0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cupsFix deferred
Red Hat Enterprise Linux 6cupsFix deferred
Red Hat Enterprise Linux 7cupsFix deferred
Red Hat Enterprise Linux 8cupsFix deferred
Red Hat Enterprise Linux 9cupsFix deferred
Red Hat Enterprise Linux 9rhel9/cupsFix deferred
Red Hat Hardened ImagescupsAffected
Red Hat OpenShift Container Platform 4rhcos/rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-178
https://bugzilla.redhat.com/show_bug.cgi?id=2530991cups: OpenPrinting CUPS: Remaining case-insensitive username matching in scheduler side paths (CVE-2026-27447 follow-up)

EPSS

Процентиль: 32%
0.00389
Низкий

3 Low

CVSS3

Связанные уязвимости

CVSS3: 3
ubuntu
6 дней назад

(Two case-insensitive comparisons on request-derived usernames outside ...)

CVSS3: 3
nvd
6 дней назад

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.

CVSS3: 3
debian
6 дней назад

Two case-insensitive comparisons on request-derived usernames outside ...

EPSS

Процентиль: 32%
0.00389
Низкий

3 Low

CVSS3