Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4323 articles · 221478 vulns · 37/41 feeds (7d)
← Back to list
8.2
CVE-2026-95511
Red Hat · Red Hat Enterprise Linux 10

Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)

Description

A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions.

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 10—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fedoralinuxcert_advisory90%
open sourceopen source cupscert_advisory90%
red hatred hat enterprise linuxmitre_affected90%
red hatred hat hardened imagesmitre_affected90%
red hatenterprise linuxcert_advisory90%

References

  • https://access.redhat.com/security/cve/CVE-2026-95511(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2537749(issue-tracking, x_refsource_REDHAT)
  • https://github.com/v12-security/pocs/tree/main/cups/cups2root

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [UNGEPATCHT] [hoch] CUPS: Schwachstelle ermöglicht Privilegieneskalation
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-95511 | Red Hat Enterprise Linux/Hardened Images 7/8/9/10 Serial Backend privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.2 NONE
CISA KEV❌ No
Actively exploited❌ No
CWECWE-269
PublishedSep 22, 2026
Last enriched1d ago
Trending Score40
Source articles2
Independent2
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-94184EXP
Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
Trending: 57
NONECVE-2026-87766EXP
Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
Trending: 53
HIGHCVE-2026-96442EXP
Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920
Trending: 47
NONECVE-2026-93676EXP
Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
Trending: 47
NONECVE-2026-93558
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
Trending: 37

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026