{"id":"CVE-2026-87876","summary":"Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up)","details":"Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.","aliases":["GHSA-r8jp-q6fh-g5r2"],"modified":"2026-09-11T08:26:28.420445Z","published":"2026-09-09T16:12:07.970Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-178"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87876.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-87876"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87876.json"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87876"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530991"},{"type":"FIX","url":"https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8"},{"type":"FIX","url":"https://github.com/OpenPrinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openprinting/cups","events":[{"introduced":"0"},{"fixed":"88e67c00c130a45f3a1edf36686f7a0b2982fef8"},{"fixed":"f56844dbe4a54a9f8e1aeb3b913fbee614156bdb"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.4.19","v2.4.18","v2.4.17","v2.4.16","v2.4.15","v2.4.14","v2.4.13","v2.4.12","v2.4.11","v2.4.10","v2.4.9","v2.4.8","v2.4.7","v2.4.6","v2.4.5","v2.4.3","v2.4.4","v2.4.2","v2.4.1","v2.4.0","v2.4rc1","v2.4b1","v2.3.3op2","v2.3.3op1","v2.3.3","v2.3.1","v2.3.0","v2.3rc1","v2.3b8","v2.3b7","v2.3b6","v2.3b5","v2.3b4","v2.3b3","v2.3b2","v2.3b1","v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.2rc1","v2.2b2","v2.2b1"],"database_specific":{"vanir_signatures_modified":"2026-09-11T08:26:28Z","vanir_signatures":[{"source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/quotas.c"},"deprecated":false,"digest":{"line_hashes":["308630171542359551084709914459108210576","32302032257830730254119659062979234592","331948191743748979578228528461707479852","81902734393913481337657042390182047002","96866944993589723318753503191188986269","74965236367896094077059693192043521086","301653179423099859626452749704189678483","57930176512453926760627502461895047074","29522552460852081715404186328339777721","337058703547184858653979637860803320100","90981260932620463595154152477514007836","278674376237624902265501983181257231317","3262928647623245577706049671233455699","99727101548028456014890436395195395004","246259689719695945578964780467100641277"],"threshold":0.9},"id":"CVE-2026-87876-076fbd7d","signature_type":"Line","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/ipp.c"},"deprecated":false,"digest":{"line_hashes":["280985054610954320514422145065281314773","47586393583207560524096765438950511699","325028282842229573432588708264875266684","45907280221965334276749423092117507024","258060308522330597749613555810438613949","80472478235415431390675754965662606349","36047747676904739504693161376947476207","50581190719680407233516031300997436430","108060925099632107455345593408655595873","298235727947926054124648255059609891614","95476363505399053581084094011577218240","315179396885888741923707024861390967121","237952360258694211229585917622218994912","301134503411126214376252797904309161916","293331364018956080842543318716025779928","281504436829307065187801371341288560646","230114875702325343394080465165201886923","42938541289982459431175422037838732572","12248349912966267664275114566667762053","63346440608210739822457513572550011295","275668230588820008686460296563872494490","247881992439716584808017847512311194167","232955498859932734625772098449062489998","113466539856358897840775922109387881976","25854516609500475358771006097906104851","315998636372439269437150397559873209968","165593700107903506848686525920255359024","170074526699178604248113182700169526501","172435057012690112857800892713112967442"],"threshold":0.9},"id":"CVE-2026-87876-0b837ce9"},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/policy.c"},"deprecated":false,"digest":{"line_hashes":["215183429129871591045278557869929555941","43313389970885284673089178980079705184","72355449381178013437460886932588630086","323743131671148201902222322694034824129","254292329762710568508531046887260266614","65754153869368488651541750488784035278","296725224696642472794467504246092227604","78119482236351163094313651481649035897","120249614225004623679324501308373531662","162553340591682749070867847018541201579","309474427528162189621233565909434743338","122670031276789816654955254708491646677","104341635199331028444684308504572469942","234121987671448058236991722013335456685","278134659335982325035194805309220428804","93650972670114338231616739775314993841","312613202634324628830512600564076635949","334832081981956922966769340043552652740","315058184882475135475482650942937787207","308236012779086350396641865367446086592","179971313848808132688133727622375432583","272952982503916884705169204231357342818","132849409953198820715711508245295293290","217227386511132120400458517505490777549","200216264129282286697252557342551134418","335261596744750399910350119249206277711","113138236924404854344077691077412655414","110362396246916548684248108172288497933","20425911675344910523353444645454434416","332389659020600079548048301667558252502","131890118944710658814384612183456155458","81296817505981919667300417375758698809"],"threshold":0.9},"id":"CVE-2026-87876-112e9143","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["132535111939739304220547508455450633589","157218389675829451010662634706461470922","324629641604173057341458290423240984260","42560085839326067720811763457323738901"],"threshold":0.9},"id":"CVE-2026-87876-2706d384","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/printers.h"}},{"deprecated":false,"digest":{"function_hash":"158154185179962272710304862588845632125","length":1819},"id":"CVE-2026-87876-43a02d9b","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/quotas.c","function":"cupsdUpdateQuota"}},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/quotas.c","function":"add_quota"},"deprecated":false,"digest":{"function_hash":"300708172949513590800384871341820141819","length":537},"id":"CVE-2026-87876-6d2b1b10","signature_type":"Function"},{"id":"CVE-2026-87876-6eddad6d","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/policy.c","function":"cupsdGetPrivateAttrs"},"deprecated":false,"digest":{"function_hash":"187753899341747795755239661318591985140","length":3490}},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/policy.c"},"deprecated":false,"digest":{"line_hashes":["65121357641243561103199217357792695957","43313389970885284673089178980079705184","72355449381178013437460886932588630086","323743131671148201902222322694034824129","254292329762710568508531046887260266614","65754153869368488651541750488784035278","296725224696642472794467504246092227604","78119482236351163094313651481649035897","120249614225004623679324501308373531662","162553340591682749070867847018541201579","309474427528162189621233565909434743338","122670031276789816654955254708491646677","104341635199331028444684308504572469942","234121987671448058236991722013335456685","278134659335982325035194805309220428804","93650972670114338231616739775314993841","312613202634324628830512600564076635949","334832081981956922966769340043552652740","315058184882475135475482650942937787207","158850273057385867929093974424612769496","91874057083941507950054596173518048757","118471337957267410797330476066673316778","265485858419252310487555964316855102244","43092067811201169316671055331697763161","86822608821091908954579775849305421009","67867978437127277443477542513470433570","28438937979663238133720260400404315091","298954160003901422864979759500766976754","53800843674934214408455801971565468996","43764640087520070946871195097236918283","308236012779086350396641865367446086592","179971313848808132688133727622375432583","272952982503916884705169204231357342818","132849409953198820715711508245295293290","217227386511132120400458517505490777549","200216264129282286697252557342551134418","335261596744750399910350119249206277711","113138236924404854344077691077412655414","110362396246916548684248108172288497933","20425911675344910523353444645454434416","332389659020600079548048301667558252502","131890118944710658814384612183456155458","81296817505981919667300417375758698809"],"threshold":0.9},"id":"CVE-2026-87876-7dc7c704","signature_type":"Line"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/quotas.c","function":"cupsdFindQuota"},"deprecated":false,"digest":{"function_hash":"140892953314946398995172078882632781859","length":405},"id":"CVE-2026-87876-9111dc62"},{"deprecated":false,"digest":{"function_hash":"300708172949513590800384871341820141819","length":537},"id":"CVE-2026-87876-b1843340","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/quotas.c","function":"add_quota"}},{"deprecated":false,"digest":{"line_hashes":["245137001554919893822707090774540675635","245148278177494122797534219404199574771","49673865612919491531293246980960720038","182055508063037689899993109035823468671","61490498943192971026109257489610722258"],"threshold":0.9},"id":"CVE-2026-87876-bd80432b","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/client.h"}},{"deprecated":false,"digest":{"line_hashes":["126629277074668200940064919231730147205","132535111939739304220547508455450633589","157218389675829451010662634706461470922","324629641604173057341458290423240984260","42560085839326067720811763457323738901"],"threshold":0.9},"id":"CVE-2026-87876-cd4c0f01","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/printers.h"}},{"deprecated":false,"digest":{"line_hashes":["219969406813403780965928816693964106590","168173757908104258658343982918487726316","123244456411926421916668477723129370260","134886726880807753216892231567815122208","110322151434141886365167924319526809774","48995054230343184121672285410158819803","271233644715206365981878285933370131918","142111032973303283956102477250244509578","96866944993589723318753503191188986269","19908161573866347296375348545508167890","74965236367896094077059693192043521086","301653179423099859626452749704189678483","57930176512453926760627502461895047074","29522552460852081715404186328339777721","290643837620299312020787249214645694572","241063355665152142772165940179875975645","156561662277207648738389969196544517418","3262928647623245577706049671233455699","213318424506694480753424552398347889189","209431766229826875122243331614874443574","99352900555407114422112817783878975904","52216506418229056622725304593208407055","92128298813943370585938359822716590717"],"threshold":0.9},"id":"CVE-2026-87876-cfd451c0","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/quotas.c"}},{"id":"CVE-2026-87876-e4b458e9","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","target":{"file":"scheduler/policy.c","function":"cupsdGetPrivateAttrs"},"deprecated":false,"digest":{"function_hash":"29836109901964053437705393082884002397","length":3413}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/quotas.c","function":"cupsdFindQuota"},"deprecated":false,"digest":{"function_hash":"140892953314946398995172078882632781859","length":405},"id":"CVE-2026-87876-e7857487"},{"digest":{"line_hashes":["280985054610954320514422145065281314773","47586393583207560524096765438950511699","325028282842229573432588708264875266684","45907280221965334276749423092117507024","258060308522330597749613555810438613949","80472478235415431390675754965662606349","36047747676904739504693161376947476207","248843794527100853489821277985841287130","37395843473556588759356767006043181320","330306635429392631538790119844811467806","320476550297080260237441464909186211379","316879344729153799941630508006073103160","187668606848671724876286187334644695184","28290511699063183968557718242508902675","298235727947926054124648255059609891614","95476363505399053581084094011577218240","315179396885888741923707024861390967121","237952360258694211229585917622218994912","280881118427864934298083785558171618216","293331364018956080842543318716025779928","281504436829307065187801371341288560646","230114875702325343394080465165201886923","42938541289982459431175422037838732572","12248349912966267664275114566667762053","63346440608210739822457513572550011295","275668230588820008686460296563872494490","247881992439716584808017847512311194167","232955498859932734625772098449062489998","113466539856358897840775922109387881976","25854516609500475358771006097906104851","315998636372439269437150397559873209968","165593700107903506848686525920255359024","170074526699178604248113182700169526501","165242004924783477003408863290207544789"],"threshold":0.9},"id":"CVE-2026-87876-e9cba502","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/ipp.c"},"deprecated":false},{"target":{"file":"scheduler/ipp.c","function":"check_quotas"},"deprecated":false,"digest":{"function_hash":"105155245393100631305347916868413235510","length":3430},"id":"CVE-2026-87876-f5d08e8c","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8"},{"digest":{"function_hash":"29098496961453139241964911668136090480","length":3441},"id":"CVE-2026-87876-fe462ec3","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","target":{"file":"scheduler/ipp.c","function":"check_quotas"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87876.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"}]}