Junglewise Threat Intelligence

CVE-2026-27447: OpenPrinting CUPS authorization bypass in cupsd via case-insensitive comparison

CVE-2026-27447 · Severity: medium · CVSS 4.8 · Published 2026-04-03

Technologies: OpenPrinting Cups. Vendors: OpenPrinting.

Executive brief

OpenPrinting CUPS is a widely used printing system for Linux and Unix-like operating systems that manages print jobs and printer configurations. A security flaw allows a user to bypass permission checks if their username is a different-case version of an authorized administrator's name (for example, 'bob' gaining the rights of 'BOB'). This could allow an unauthorized person to manage printers, view sensitive documents, or modify system-wide printing settings.

Technical details

An authorization bypass exists in the CUPS daemon (cupsd) within the `scheduler/auth.c` component. The vulnerability stems from the use of case-insensitive string comparison (via `_cups_strcasecmp`) when validating if a requesting user belongs to an authorized group, such as 'lpadmin'. On Linux systems where usernames are case-sensitive, an attacker can create or use an account that differs only by case from an authorized user to gain elevated privileges. This allows unauthorized access to restricted operations including printer management and configuration modification. The issue is addressed in version 2.4.17.

Affected products

  • OpenPrinting CUPS <= 2.4.16

Timeline

  • 2026-03-31: advisory: GitHub Security Advisory GHSA-v987-m8hp-phj9 published
  • 2026-04-03: disclosed: CVE-2026-27447 published
  • 2026-04-03: patched: Fix committed to master branch

References

Related threats