Logo
vulnerabilityCVE-2026-27447
Name
CVE-2026-27447
Source
NVD ( link)Debian ( link)
Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
cups
Patched

Vulnerability Ratings#


4.8
CVSSv31
6.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.4.17
Not Affected
buildroot
master
2.4.19
Not Affected
yocto
kirkstone
2.4.2
Exploitable
yocto
master
2.4.19
Not Affected

Resolved with patches#


cups (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix unauthenticated print policies (Issue #1557)
Michael R Sweet <msweet@msweet.org>
CVE-2026-27447
2
CVE-2026-27447: The scheduler treated local user and group
Michael R Sweet <msweet@msweet.org>
CVE-2026-27447
3
Fix cupsd crash if user does not exist on server
Zdenek Dohnal <zdohnal@redhat.com>
CVE-2026-27447