---
id: CVE-2026-27447
title: >-
  OpenPrinting CUPS is an open source printing system for Linux and other
  Unix-like operating systems
summary: >-
  OpenPrinting CUPS is an open source printing system for Linux and other
  Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd)
  contains an authorization bypass vulnerability due to case-insensitive
  username compar…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N'
cwe:
  - CWE-863
vendor: openprinting
product: cups
affected:
  - cups <= 2.4.16
published: '2026-04-03'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27447'
references:
  - url: >-
      https://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220
    label: security-advisories@github.com
  - url: >-
      https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00317
epssPercentile: 0.2487
ingestedAt: '2026-07-25T22:05:04.986Z'
---

## Overview

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.

## Affected

- `cups <= 2.4.16`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
