Vulnerabilidad · Publicado 22/09/2026
Se identificó una vulnerabilidad de escalada de privilegios (CVSS 8.2) en CUPS cuando se utiliza con el backend serial de cups-filters. Un usuario local miembro del grupo lpadmin puede configurar una impresora con backend serial privilegiado para escribir datos arbitrarios en cualquier archivo del sistema con permisos de root. Esta falla afecta especialmente a infraestructuras de impresión compartida en empresas medianas y grandes en México y Latinoamérica.
A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does not restrict the path component of non-file device URIs, so the root-privileged backend can write attacker-controlled print data to an arbitrary file. This can be used to change security-sensitive CUPS configuration and ultimately achieve root code execution. Exploitation requires local lpadmin group membership and a serial backend binary installed with root-only permissions.
Score: 8.2/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-269
Publicado en NIST NVD.