Junglewise Threat Intelligence

CVE-2026-95511: CUPS configuration file overwrite in serial queue creation

CVE-2026-95511 · Severity: info · Published 2026-09-22

Vendors: Apple.

Executive brief

CUPS is a printing service that manages print queues on Unix systems. An administrator member of the CUPS admin group (lpadmin) could create a specially crafted serial queue to overwrite the CUPS configuration file. Since the attack requires pre-existing administrative privileges granted by a superuser, this does not represent a privilege escalation or security boundary violation.

Technical details

A vulnerability in CUPS serial queue creation allows overwriting the cups-files.conf configuration file. The attack requires membership in the SystemGroups (lpadmin), which is an opt-in administrative role that must be explicitly granted by a superuser. No privilege boundary is crossed since the attacker already holds administrative rights within CUPS.

Affected products

  • Apple CUPS

Timeline

  • 2026-09-22: disclosed