A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-95511 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.
CVE-2026-95511
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.2
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 0%
- EPSS %ILE
- 2%
- KEV
- Not listed
Published
September 22, 2026
Last Modified
September 22, 2026
Advisory Details (3)
Auto-updated Sep 22, 2026pocs/cups/cups2root at main · v12-security/pocs · GitHub
https://github.com/v12-security/pocs/tree/main/cups/cups2root2537749 – (CVE-2026-95511) CVE-2026-95511 cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)
https://bugzilla.redhat.com/show_bug.cgi?id=2537749CVE-2026-95511 - Red Hat Customer Portal
Affected: Red Hat Enterprise Linux 8, 9, and 10, and Fedora, ship cups-filters with the serial backend and are affected. Products that s
https://access.redhat.com/security/cve/CVE-2026-95511Vendor Advisories for CVE-2026-95511(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 14× in last 7d / 14× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-23 03:10 UTCEG score recompute▼ 8.20
- 2026-09-23 03:10 UTCGHSA enrichment
- 2026-09-22 16:01 UTCEPSS rescore
- 2026-09-22 14:20 UTCEG score recompute
- 2026-09-22 14:20 UTCGHSA enrichment
- 2026-09-22 13:27 UTCEG score recompute
- 2026-09-22 13:27 UTCGHSA enrichment
- 2026-09-22 11:35 UTCEG score recompute
- 2026-09-22 11:35 UTCGHSA enrichment
- 2026-09-22 10:56 UTCGHSA enrichment
- 2026-09-22 10:27 UTCEG score recompute
- 2026-09-22 10:26 UTCGHSA enrichment
- 2026-09-22 08:49 UTCEG score recompute
- 2026-09-22 08:45 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-95511?
When was CVE-2026-95511 disclosed?
Is CVE-2026-95511 actively exploited?
What is the CVSS score of CVE-2026-95511?
How do I remediate CVE-2026-95511?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-95511
Is Your Infrastructure Affected by CVE-2026-95511?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.