{"id":"CVE-2026-95511","title":"Rejected reason: Not a vulnerability","summary":"Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"Red Hat","product":"cups-filters","affected":["cups-filters","cups-filters","cups-filters","cups-filters","cups (all versions)"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T15:17:25.797","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95511","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-95511","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2537749","label":"secalert@redhat.com"},{"url":"https://github.com/v12-security/pocs/tree/main/cups/cups2root","label":"secalert@redhat.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00117,"epssPercentile":0.01924,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-22T13:09:29.372308Z"},"cvssSource":"nvd","ingestedAt":"2026-09-22T09:01:05.605Z","slug":"CVE-2026-95511","body":"## Overview\n\nRejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":209064,"id":"CVE-2026-95511","ts":1790085894949,"field":"exploit_available","old":"false","new":"true"}]}