#VU124814 Incorrect authorization in cups - CVE-2026-27447
Published: April 2, 2026
cups
OpenPrinting
Description
The vulnerability allows a remote user to gain unauthorized access to restricted operations.
The vulnerability exists due to improper access control in the CUPS daemon (cupsd) when performing authorization checks. A remote privileged user can exploit case-insensitive username comparison during group-member lookup to gain unauthorized access to restricted operations.
User interaction is required to exploit this vulnerability.