← back
CVE-2026-27447

OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup

CVSS 4.8 MEDIUMEPSS 0.3%CWE-863
In short

CUPS printing system has a flaw where usernames are compared without considering uppercase vs. lowercase letters, allowing someone to bypass access restrictions by using a slightly different version of an authorized username.

Technical detail

CWE-863 authorization bypass in CUPS versions ≤2.4.16 caused by case-insensitive username comparison during privilege checks. An unprivileged local user can exploit this to perform restricted operations by authenticating with a username variant differing only in case from an authorized account, bypassing group-member validation logic.

Summary generated and translated by AI from the official description.
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
Affected products
OpenPrinting · cups

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →