Description
Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.
Published: 2026-09-22
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root) cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Cups
Cups cups
Redhat
Redhat enterprise Linux
Redhat hardened Images
Vendors & Products Cups
Cups cups
Redhat
Redhat enterprise Linux
Redhat hardened Images

Tue, 22 Sep 2026 15:30:00 +0000


Tue, 22 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions. Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 22 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions.
Title Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-269
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cups Cups
Redhat Enterprise Linux Hardened Images
cve-icon MITRE

Status: REJECTED

Assigner: redhat

Published:

Updated: 2026-09-22T14:19:13.126Z

Reserved: 2026-09-22T07:58:16.551Z

Link: CVE-2026-95511

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2026-09-22T09:17:06.217

Modified: 2026-09-22T15:17:25.797

Link: CVE-2026-95511

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T01:07:08Z

Links: CVE-2026-95511 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T09:13:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management