CVE-2026-105326: Cups: cups: argument injection in mailto notifier via notify-recipient-uri

Published Oct 5, 2026
·
Updated

An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user.

Other sources

CUPS (Common UNIX Printing System) scheduler accepts IPP Create-Printer-Subscription requests with a notify-recipient-uri attribute. In scheduler/ipp.c, createprintersubscription validates only the URI scheme (notifier type) and does not validate the recipient address portion of mailto: URIs.

When a subscribed event fires, the mailto notifier in notifier/mailto.c passes the recipient string verbatim as a command-line argument to the configured sendmail binary (pipesendmail / execvp) without rejecting leading "-" characters or inserting a "--" separator. A notify-recipient-uri such as mailto:-tC/path/to/crafted.cf is therefore interpreted by traditional sendmail as option arguments (argument injection, CWE-88).

Combined with anonymous Create-Printer-Subscription under default cupsd policy and the ability to stage attacker-controlled files in the CUPS spool via Print-Job, this can chain to arbitrary command execution as the CUPS filter user (lp) when cupsd is network-reachable and a traditional sendmail implementation that honors -C is installed and configured in mailto.conf.

Upstream advisory: GHSA-r4wf-366f-f6g3 (OpenPrinting/cups). Upstream affected version cited: 2.4.7. Upstream fixes on master (1244ed9) and 2.4.x (611d1bd) validate notification email addresses and harden sendmail invocation.

PSIRT ticket: PSIRTSUPT-24443

— Red Hat

Affected Software

1 affected component
OpenPrinting CUPS=2.4.7

Event History

Oct 5, 2026
Data Sourced
via Red Hat·08:48 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to attempt exploitation?

The attacker must be able to reach the CUPS service and submit an IPP Create-Printer-Subscription request. The supplied notify-recipient-uri must use the mailto scheme and contain a crafted recipient value beginning with a hyphen.

2

When is a deployment exposed in practice?

Exposure requires email notification to be configured and a reachable CUPS scheduler that accepts the subscription request. Whether the injected argument can produce command execution also depends on the installed mail transfer agent's handling of command-line options.

3

What privileges could affected command execution have?

If exploitation succeeds, attacker-controlled commands may execute with the privileges of the CUPS service user. The issue does not indicate execution as an arbitrary user or elevated system administrator account.

4

How can I identify potentially affected subscription activity?

Review CUPS printer subscriptions for notify-recipient-uri values using the mailto scheme, especially recipient portions that begin with a hyphen. Also determine whether subscribed events have fired, since the recipient is passed to the configured sendmail program when an event is delivered.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203