CVE-2026-27447: OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
Last updated 8 June 2026
Other sources
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.
— MITRE
OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cupsto a version that resolves this vulnerability.Fixed in 2.4.18-1 - Upgrade
Upgrade
OpenPrinting CUPS (cupsd)to a version that resolves this vulnerability.Fixed in 2.4.16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27447?
CVE-2026-27447 has been classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-27447?
To mitigate CVE-2026-27447, upgrade to OpenPrinting CUPS version 2.4.17 or later.
What is the impact of CVE-2026-27447?
CVE-2026-27447 allows attackers to bypass authorization checks, potentially leading to unauthorized control over the printing system.
Which versions of OpenPrinting CUPS are affected by CVE-2026-27447?
CVE-2026-27447 affects OpenPrinting CUPS versions 2.4.16 and earlier.
Who is affected by CVE-2026-27447?
Users and organizations running affected versions of OpenPrinting CUPS are at risk of exploitation due to CVE-2026-27447.