Junglewise Threat Intelligence

CVE-2026-87876: CUPS scheduler case-insensitive username comparison in ACL validation

CVE-2026-87876 · Severity: low · CVSS 3 · Published 2026-09-09

Technologies: OpenPrinting Cups. Vendors: OpenPrinting.

Executive brief

CUPS is a widely-used printing system that manages access to network printers through username-based access controls. A flaw in how the scheduler compares usernames allows attackers in certain configurations to bypass printer access restrictions and unauthorized filtering of private attributes by exploiting case-sensitive/insensitive comparison logic, potentially gaining access to restricted print queues or viewing sensitive print job metadata.

Technical details

The vulnerability exists in CUPS's scheduler due to two case-insensitive string comparisons performed on request-derived usernames outside the main authorization code path. These comparisons occur in printer ACL (Access Control List) validation and private-attribute filtering logic. An attacker can craft usernames that differ only in case (e.g., "admin" vs "Admin") to bypass username-based access controls, provided the system is configured to enforce such controls. The flaw requires network access to a CUPS printer server and knowledge of valid usernames. A patch addressing the comparison logic is expected from the CUPS maintainers.

Affected products

  • OpenPrinting CUPS <UNKNOWN>

Timeline

  • 2026-09-09: disclosed

References

Related threats