Sceawere
Vulnerability Detail
CVE-2026-105326UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CUPS Argument Injection Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.5
- Creation Date
- 2h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.5",
"pubDate": "2026-10-05T19:17:16.393Z",
"pubdate": "2026-10-05T19:17:16.393Z",
"executiveSummary": "A critical argument injection vulnerability exists within the CUPS scheduler, specifically concerning the handling of email notifications.\nThe flaw originates from improper input validation when processing 'mailto' notify-recipient-uri values, allowing attacker-supplied strings to be passed as command-line arguments to the system's 'sendmail' executable.\nA remote, unauthenticated attacker can exploit this weakness to perform command injection, potentially resulting in arbitrary code execution with the privileges of the CUPS service user.\nThe impact depends heavily on the specific Mail Transfer Agent (MTA) installed and the configuration of the CUPS daemon relative to network exposure.\nSuccessful exploitation requires the attacker to submit a crafted printer subscription request containing a malicious recipient URI starting with a hyphen, which the 'sendmail' utility interprets as command-line flags rather than positional arguments.\nOrganizations running CUPS with notification services enabled in exposed network environments are at elevated risk of system compromise.",
"technicalDetails": "The vulnerability resides in the CUPS scheduler component responsible for processing subscription requests and triggering notifications. When a user requests a print subscription with an email notification type, the scheduler utilizes the 'mailto' protocol to dispatch alerts. The critical failure occurs during the interface between the CUPS scheduler and the underlying system mail delivery utility, typically 'sendmail'.\nThe scheduler fails to sanitize the 'notify-recipient-uri' input before constructing the command string for the MTA. In POSIX-compliant systems, many utilities—including 'sendmail'—interpret strings beginning with a hyphen ('-') as command-line options rather than data. By injecting a recipient string starting with '-', an attacker can pass arbitrary flags to 'sendmail'.\nThe attack flow proceeds as follows: First, the attacker reaches the CUPS service via the network. Second, the attacker initiates a printer subscription request (e.g., via IPP) specifying a malicious URI parameter. This URI contains a carefully crafted recipient string that injects unintended command-line options into the 'sendmail' execution context. For instance, an attacker could attempt to leverage specific MTA flags to redirect output, specify configuration files, or manipulate the message processing pipeline.\nBecause the 'sendmail' command is executed by the CUPS service, the injected commands inherit the service's privileges. If the service is running with elevated permissions (e.g., as root or a specialized system user), the attacker gains the ability to execute commands within that security context. This effectively bypasses standard access control mechanisms, provided the attacker can reach the network port on which CUPS is listening.\nThe exploitability of this flaw is gated by two factors: the local MTA configuration and the network reachability of the CUPS service. Different MTAs have varying command-line interfaces; the degree of control an attacker exerts over the shell execution depends on whether the MTA allows flags that could result in arbitrary file writes or binary execution. The vulnerability does not require authentication to the CUPS service, as subscription requests are often accepted by default in many standard configurations, significantly widening the attack surface for internal and external network-based threats."
}