CVE-2026-87876
LOW
NVD
CVSS Score
3
Severity
LOW
Published
Sep 09, 2026
Vendor
unknown
Description
Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.