Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Restrict network access to the CUPS service (port 631/tcp) to trusted hosts only, and avoid exposing cupsd to untrusted networks. If email notifications are not required, do not configure mailto subscriptions or remove/disable the mailto notifier. Ensure only a trusted mail transfer agent is installed and referenced from CUPS mailto configuration. Monitor for unexpected printer subscriptions and unusual sendmail activity from the lp user.
Mon, 05 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user. | |
| Title | Cups: cups: argument injection in mailto notifier via notify-recipient-uri | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-05T18:58:56.161Z
Reserved: 2026-10-05T08:47:01.523Z
Link: CVE-2026-105326
No data.
Status : Received
Published: 2026-10-05T19:17:16.393
Modified: 2026-10-05T19:17:16.393
Link: CVE-2026-105326
No data.
OpenCVE Enrichment
No data.