Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-95511
Red Hat Red Hat Enterprise Linux 10 — Cups: cups-filters: cups-filters: lpadmin can escalate to root via privileged serial backend (cups2root)
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L H N C H H H 8.2 .0012 1.9 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 10 unspecified —
Red Hat Enterprise Linux 7 unspecified —
Red Hat Enterprise Linux 8 unspecified —
Red Hat Enterprise Linux 9 unspecified —
Red Hat Hardened Images unspecified —
TIMELINE
Sep 22 REJECTED — CVE-2026-95511 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA.
Sep 22 Reserved by redhat
Sep 22 Published (CNA: redhat)
Description
Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 22, 2026 | REJECTED | REJECTED — CVE-2026-95511 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA. |
| September 22, 2026 | Reserved | Reserved by redhat |
| September 22, 2026 | Published | Published (CNA: redhat) |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | — |
| Red Hat | Red Hat Hardened Images | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-95511 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.