CVE-2026-87876
Dashboard / Vulnerabilities / CVE-2026-87876
Summary: Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up)
Details: Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
References: https://access.redhat.com/downloads/content/package-browser/, https://access.redhat.com/security/cve/CVE-2026-87876, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87876.json, https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2, https://nvd.nist.gov/vuln/detail/CVE-2026-87876, https://bugzilla.redhat.com/show_bug.cgi?id=2530991, https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8, https://github.com/OpenPrinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb
Affected packages
Package
Name:
Purl:
