CVE-2026-105326
Public on 2026-10-05
Modified on 2026-10-08
Description
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | cups | Pending Fix | ||
| Amazon Linux 2023 | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups-browsed | Not Affected | ||
| Amazon Linux 2 - Core | cups-filters | Not Affected | ||
| Amazon Linux 2023 | cups-filters | Not Affected | ||
| Amazon Linux 2027 Preview | cups-filters | Not Affected | ||
| Amazon Linux 2 - Core | cups-pk-helper | Not Affected | ||
| Amazon Linux 2023 | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | cups-pk-helper | Not Affected | ||
| Amazon Linux 2 - Core | filesystem | Not Affected | ||
| Amazon Linux 2023 | filesystem | Not Affected | ||
| Amazon Linux 2027 Preview | filesystem | Not Affected | ||
| Amazon Linux 2027 Preview | libcupsfilters | Not Affected | ||
| Amazon Linux 2 - Core | python-cups | Not Affected | ||
| Amazon Linux 2023 | python-cups | Not Affected | ||
| Amazon Linux 2027 Preview | python-cups | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |