Skip to content
Red HatCVE-2026-87876

Two case-insensitive comparisons on request-derived usernames outside the main...

Low3.0CVE-2026-87876 · Published Sep 9, 2026 · updated Sep 21, 2026

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat memcached cache plugin of the community: remote code execution
High8.1Sep 9
Red Hat Enterprise Linux 10: out-of-bounds read
Medium4.3Sep 9
A flaw was found in SSSD's IdP authentication provider
High7.5Sep 9
Red Hat Ceph Storage 5: improper certificate validation
Medium6.8Sep 9
Red Hat FreeIPA. An unauthenticated remote attacker: cross-site scripting
High8.1Sep 9
Red Hat bubblewrap. During sandbox setup: link following
High8.8Sep 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.