CVE-2026-87876 vulnerability in Red Hat Products
Published on September 9, 2026
Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up)
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 15 days later.
Weakness Type
Improper Handling of Case Sensitivity
The software does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Products Associated with CVE-2026-87876
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.