Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105326— Cups: cups: argument injection in mailto notifier via notify-recipient-uri

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CUPS 中存在一个参数注入漏洞。当配置了电子邮件通知功能时,CUPS 调度器会接受打印机订阅请求,其中包含以 前缀开头的 参数。 通知程序会将收件人地址直接传递给配置好的 程序,而未对该地址进行充分的安全检查,无法防止其被解释为命令行选项。 如果远程攻击者能够访问 CUPS 服务,则可通过构造以减号( )开头的收件人值,从而干扰 的正常行为。该漏洞的成功利用取决于所安装的邮件传输代理(MTA)以及 CUPS 的网络暴露情况,可能导致以 CUPS 服务用户的权限执行攻击者控制的命令。

CVSS 2.5 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 5

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 10 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
Red Hat Red Hat Enterprise Linux 9 any affected
any affected
Red Hat Red Hat Hardened Images any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105326

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cups: cups: argument injection in mailto notifier via notify-recipient-uri
Source: CVE Program / CVE List V5
Vulnerability Description
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
参数注入或修改
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1

II. Public POCs for CVE-2026-105326

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105326

请登录查看更多情报信息。

Other References for CVE-2026-105326 (5)

Same Patch Batch · Red Hat · 2026-10-05 · 12 CVEs total

CVE-2026-101919 8.8 HIGH Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to contro
CVE-2026-71299 6.5 MEDIUM Maestro: maestro: rest api write endpoints registered without authentication middleware
CVE-2026-105306 6.5 MEDIUM Keycloak-services: keycloak-services: token introspection audience bypass via dynamic clie
CVE-2026-71298 6.4 MEDIUM Maestro: sql identifier injection via properties.* search filter and orderby field
CVE-2026-105302 5.7 MEDIUM Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access
CVE-2026-104030 5.5 MEDIUM Sssd: sssd: denial of service via out-of-bounds read during passkey parsing
CVE-2026-71297 5.4 MEDIUM Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional
CVE-2026-102295 5.4 MEDIUM Quay: quay: dom-based cross-site scripting via oauth local callback format=json parameter
CVE-2026-102576 4.2 MEDIUM Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on signin page
CVE-2026-105301 4.0 MEDIUM Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker
CVE-2026-104029 3.3 LOW Sssd: sssd: denial of service via out-of-bounds read in autofs responder

IV. Related Vulnerabilities

V. Comments for CVE-2026-105326

No comments yet


Leave a comment