Impact
An argument injection flaw in the CUPS mailto notifier allows a crafted recipient address to be passed to the configured sendmail program without filtering command‑line options, enabling an attacker to influence sendmail’s behavior. If successful, the attacker can execute arbitrary commands with the privileges of the CUPS service user. The CVSS score of 2.5 indicates a low overall severity, but the potential for remote code execution remains significant because it can occur over the network without local system access.
Affected Systems
The flaw affects CUPS installations on Red Hat Enterprise Linux 10, 8, 9, and Red Hat Hardened Images. These distributions ship CUPS as part of the OS packages and therefore are within the scope of the vulnerability.
Risk and Exploitability
The attack vector is likely remote via TCP port 631, the standard CUPS service port. Exploitation requires an exposed CUPS service and a mail transfer agent that accepts command‑line options from the recipient address. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, implying a relatively low likelihood of widespread exploitation at this time. Nonetheless, the potential to execute commands as the CUPS user warrants immediate mitigation.
OpenCVE Enrichment