Sceawere

Vulnerability Detail

CVE-2026-105326UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CUPS Argument Injection Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
2.5
Creation Date
2h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.5",
  "pubDate": "2026-10-05T19:17:16.393Z",
  "pubdate": "2026-10-05T19:17:16.393Z",
  "executiveSummary": "A critical argument injection vulnerability exists within the CUPS scheduler, specifically concerning the handling of email notifications.\nThe flaw originates from improper input validation when processing 'mailto' notify-recipient-uri values, allowing attacker-supplied strings to be passed as command-line arguments to the system's 'sendmail' executable.\nA remote, unauthenticated attacker can exploit this weakness to perform command injection, potentially resulting in arbitrary code execution with the privileges of the CUPS service user.\nThe impact depends heavily on the specific Mail Transfer Agent (MTA) installed and the configuration of the CUPS daemon relative to network exposure.\nSuccessful exploitation requires the attacker to submit a crafted printer subscription request containing a malicious recipient URI starting with a hyphen, which the 'sendmail' utility interprets as command-line flags rather than positional arguments.\nOrganizations running CUPS with notification services enabled in exposed network environments are at elevated risk of system compromise.",
  "technicalDetails": "The vulnerability resides in the CUPS scheduler component responsible for processing subscription requests and triggering notifications. When a user requests a print subscription with an email notification type, the scheduler utilizes the 'mailto' protocol to dispatch alerts. The critical failure occurs during the interface between the CUPS scheduler and the underlying system mail delivery utility, typically 'sendmail'.\nThe scheduler fails to sanitize the 'notify-recipient-uri' input before constructing the command string for the MTA. In POSIX-compliant systems, many utilities—including 'sendmail'—interpret strings beginning with a hyphen ('-') as command-line options rather than data. By injecting a recipient string starting with '-', an attacker can pass arbitrary flags to 'sendmail'.\nThe attack flow proceeds as follows: First, the attacker reaches the CUPS service via the network. Second, the attacker initiates a printer subscription request (e.g., via IPP) specifying a malicious URI parameter. This URI contains a carefully crafted recipient string that injects unintended command-line options into the 'sendmail' execution context. For instance, an attacker could attempt to leverage specific MTA flags to redirect output, specify configuration files, or manipulate the message processing pipeline.\nBecause the 'sendmail' command is executed by the CUPS service, the injected commands inherit the service's privileges. If the service is running with elevated permissions (e.g., as root or a specialized system user), the attacker gains the ability to execute commands within that security context. This effectively bypasses standard access control mechanisms, provided the attacker can reach the network port on which CUPS is listening.\nThe exploitability of this flaw is gated by two factors: the local MTA configuration and the network reachability of the CUPS service. Different MTAs have varying command-line interfaces; the degree of control an attacker exerts over the shell execution depends on whether the MTA allows flags that could result in arbitrary file writes or binary execution. The vulnerability does not require authentication to the CUPS service, as subscription requests are often accepted by default in many standard configurations, significantly widening the attack surface for internal and external network-based threats."
}
CVE-2026-105326: CUPS Argument Injection Vulnerability (LOW Severity, CVSS: 2.5) | Sceawere