Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-178"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87876.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87876.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"308630171542359551084709914459108210576",
"32302032257830730254119659062979234592",
"331948191743748979578228528461707479852",
"81902734393913481337657042390182047002",
"96866944993589723318753503191188986269",
"74965236367896094077059693192043521086",
"301653179423099859626452749704189678483",
"57930176512453926760627502461895047074",
"29522552460852081715404186328339777721",
"337058703547184858653979637860803320100",
"90981260932620463595154152477514007836",
"278674376237624902265501983181257231317",
"3262928647623245577706049671233455699",
"99727101548028456014890436395195395004",
"246259689719695945578964780467100641277"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-076fbd7d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/quotas.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"280985054610954320514422145065281314773",
"47586393583207560524096765438950511699",
"325028282842229573432588708264875266684",
"45907280221965334276749423092117507024",
"258060308522330597749613555810438613949",
"80472478235415431390675754965662606349",
"36047747676904739504693161376947476207",
"50581190719680407233516031300997436430",
"108060925099632107455345593408655595873",
"298235727947926054124648255059609891614",
"95476363505399053581084094011577218240",
"315179396885888741923707024861390967121",
"237952360258694211229585917622218994912",
"301134503411126214376252797904309161916",
"293331364018956080842543318716025779928",
"281504436829307065187801371341288560646",
"230114875702325343394080465165201886923",
"42938541289982459431175422037838732572",
"12248349912966267664275114566667762053",
"63346440608210739822457513572550011295",
"275668230588820008686460296563872494490",
"247881992439716584808017847512311194167",
"232955498859932734625772098449062489998",
"113466539856358897840775922109387881976",
"25854516609500475358771006097906104851",
"315998636372439269437150397559873209968",
"165593700107903506848686525920255359024",
"170074526699178604248113182700169526501",
"172435057012690112857800892713112967442"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-0b837ce9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/ipp.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"215183429129871591045278557869929555941",
"43313389970885284673089178980079705184",
"72355449381178013437460886932588630086",
"323743131671148201902222322694034824129",
"254292329762710568508531046887260266614",
"65754153869368488651541750488784035278",
"296725224696642472794467504246092227604",
"78119482236351163094313651481649035897",
"120249614225004623679324501308373531662",
"162553340591682749070867847018541201579",
"309474427528162189621233565909434743338",
"122670031276789816654955254708491646677",
"104341635199331028444684308504572469942",
"234121987671448058236991722013335456685",
"278134659335982325035194805309220428804",
"93650972670114338231616739775314993841",
"312613202634324628830512600564076635949",
"334832081981956922966769340043552652740",
"315058184882475135475482650942937787207",
"308236012779086350396641865367446086592",
"179971313848808132688133727622375432583",
"272952982503916884705169204231357342818",
"132849409953198820715711508245295293290",
"217227386511132120400458517505490777549",
"200216264129282286697252557342551134418",
"335261596744750399910350119249206277711",
"113138236924404854344077691077412655414",
"110362396246916548684248108172288497933",
"20425911675344910523353444645454434416",
"332389659020600079548048301667558252502",
"131890118944710658814384612183456155458",
"81296817505981919667300417375758698809"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-112e9143",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/policy.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"132535111939739304220547508455450633589",
"157218389675829451010662634706461470922",
"324629641604173057341458290423240984260",
"42560085839326067720811763457323738901"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-2706d384",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/printers.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "158154185179962272710304862588845632125",
"length": 1819
},
"id": "CVE-2026-87876-43a02d9b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/quotas.c",
"function": "cupsdUpdateQuota"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "300708172949513590800384871341820141819",
"length": 537
},
"id": "CVE-2026-87876-6d2b1b10",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/quotas.c",
"function": "add_quota"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "187753899341747795755239661318591985140",
"length": 3490
},
"id": "CVE-2026-87876-6eddad6d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/policy.c",
"function": "cupsdGetPrivateAttrs"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"65121357641243561103199217357792695957",
"43313389970885284673089178980079705184",
"72355449381178013437460886932588630086",
"323743131671148201902222322694034824129",
"254292329762710568508531046887260266614",
"65754153869368488651541750488784035278",
"296725224696642472794467504246092227604",
"78119482236351163094313651481649035897",
"120249614225004623679324501308373531662",
"162553340591682749070867847018541201579",
"309474427528162189621233565909434743338",
"122670031276789816654955254708491646677",
"104341635199331028444684308504572469942",
"234121987671448058236991722013335456685",
"278134659335982325035194805309220428804",
"93650972670114338231616739775314993841",
"312613202634324628830512600564076635949",
"334832081981956922966769340043552652740",
"315058184882475135475482650942937787207",
"158850273057385867929093974424612769496",
"91874057083941507950054596173518048757",
"118471337957267410797330476066673316778",
"265485858419252310487555964316855102244",
"43092067811201169316671055331697763161",
"86822608821091908954579775849305421009",
"67867978437127277443477542513470433570",
"28438937979663238133720260400404315091",
"298954160003901422864979759500766976754",
"53800843674934214408455801971565468996",
"43764640087520070946871195097236918283",
"308236012779086350396641865367446086592",
"179971313848808132688133727622375432583",
"272952982503916884705169204231357342818",
"132849409953198820715711508245295293290",
"217227386511132120400458517505490777549",
"200216264129282286697252557342551134418",
"335261596744750399910350119249206277711",
"113138236924404854344077691077412655414",
"110362396246916548684248108172288497933",
"20425911675344910523353444645454434416",
"332389659020600079548048301667558252502",
"131890118944710658814384612183456155458",
"81296817505981919667300417375758698809"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-7dc7c704",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/policy.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "140892953314946398995172078882632781859",
"length": 405
},
"id": "CVE-2026-87876-9111dc62",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/quotas.c",
"function": "cupsdFindQuota"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "300708172949513590800384871341820141819",
"length": 537
},
"id": "CVE-2026-87876-b1843340",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/quotas.c",
"function": "add_quota"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"245137001554919893822707090774540675635",
"245148278177494122797534219404199574771",
"49673865612919491531293246980960720038",
"182055508063037689899993109035823468671",
"61490498943192971026109257489610722258"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-bd80432b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/client.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"126629277074668200940064919231730147205",
"132535111939739304220547508455450633589",
"157218389675829451010662634706461470922",
"324629641604173057341458290423240984260",
"42560085839326067720811763457323738901"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-cd4c0f01",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/printers.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"219969406813403780965928816693964106590",
"168173757908104258658343982918487726316",
"123244456411926421916668477723129370260",
"134886726880807753216892231567815122208",
"110322151434141886365167924319526809774",
"48995054230343184121672285410158819803",
"271233644715206365981878285933370131918",
"142111032973303283956102477250244509578",
"96866944993589723318753503191188986269",
"19908161573866347296375348545508167890",
"74965236367896094077059693192043521086",
"301653179423099859626452749704189678483",
"57930176512453926760627502461895047074",
"29522552460852081715404186328339777721",
"290643837620299312020787249214645694572",
"241063355665152142772165940179875975645",
"156561662277207648738389969196544517418",
"3262928647623245577706049671233455699",
"213318424506694480753424552398347889189",
"209431766229826875122243331614874443574",
"99352900555407114422112817783878975904",
"52216506418229056622725304593208407055",
"92128298813943370585938359822716590717"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-cfd451c0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/quotas.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "29836109901964053437705393082884002397",
"length": 3413
},
"id": "CVE-2026-87876-e4b458e9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/policy.c",
"function": "cupsdGetPrivateAttrs"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "140892953314946398995172078882632781859",
"length": 405
},
"id": "CVE-2026-87876-e7857487",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/quotas.c",
"function": "cupsdFindQuota"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"280985054610954320514422145065281314773",
"47586393583207560524096765438950511699",
"325028282842229573432588708264875266684",
"45907280221965334276749423092117507024",
"258060308522330597749613555810438613949",
"80472478235415431390675754965662606349",
"36047747676904739504693161376947476207",
"248843794527100853489821277985841287130",
"37395843473556588759356767006043181320",
"330306635429392631538790119844811467806",
"320476550297080260237441464909186211379",
"316879344729153799941630508006073103160",
"187668606848671724876286187334644695184",
"28290511699063183968557718242508902675",
"298235727947926054124648255059609891614",
"95476363505399053581084094011577218240",
"315179396885888741923707024861390967121",
"237952360258694211229585917622218994912",
"280881118427864934298083785558171618216",
"293331364018956080842543318716025779928",
"281504436829307065187801371341288560646",
"230114875702325343394080465165201886923",
"42938541289982459431175422037838732572",
"12248349912966267664275114566667762053",
"63346440608210739822457513572550011295",
"275668230588820008686460296563872494490",
"247881992439716584808017847512311194167",
"232955498859932734625772098449062489998",
"113466539856358897840775922109387881976",
"25854516609500475358771006097906104851",
"315998636372439269437150397559873209968",
"165593700107903506848686525920255359024",
"170074526699178604248113182700169526501",
"165242004924783477003408863290207544789"
],
"threshold": 0.9
},
"id": "CVE-2026-87876-e9cba502",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/ipp.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "105155245393100631305347916868413235510",
"length": 3430
},
"id": "CVE-2026-87876-f5d08e8c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8",
"target": {
"file": "scheduler/ipp.c",
"function": "check_quotas"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "29098496961453139241964911668136090480",
"length": 3441
},
"id": "CVE-2026-87876-fe462ec3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb",
"target": {
"file": "scheduler/ipp.c",
"function": "check_quotas"
}
}
]
"2026-09-11T08:26:28Z"