Schwachstellenklasse
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Quellen
- https://access.redhat.com/errata/RHSA-2026:67568
- https://access.redhat.com/security/cve/CVE-2026-87876
- https://bugzilla.redhat.com/show_bug.cgi?id=2530991
- https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8
- https://github.com/OpenPrinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.