CVE-2026-87876
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
- Published Sep 9, 2026
- CVSS 3.0 low
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available