CVE-2026-27447 is an authorization bypass vulnerability affecting OpenPrinting CUPS daemon (cupsd) versions 2.4.16 and prior, caused by case-insensitive username comparisons during authorization. This flaw allows an unprivileged user to gain unauthorized access to restricted operations. Rated as MEDIUM severity (CVSS 4.8), exploitation requires network access, high attack complexity, and high privileges, with a high impact on confidentiality. There is currently no evidence of active exploitation, no public exploit code, and minimal community attention, with no patches available at the time of publication.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.16CPE matchmatch criteria | cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.