CVE-2026-87876

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.

Credits

Red Hat would like to thank arbor-s (Independent Security Researcher) for reporting this issue.

References