Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Amazon Linux 2023: CVE-2022-26691: Important priority package update for cups

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
May 25, 2022
Added
Feb 17, 2025
Modified
Jul 9, 2025

Description

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
An authorization vulnerability was found in the CUPS printing system. This security vulnerability occurs when local authorization happens. This flaw allows an attacker to authenticate to CUPS as root/admin without the 32-byte secret key and perform arbitrary code execution.

Solutions

amazon-linux-2023-upgrade-cupsamazon-linux-2023-upgrade-cups-clientamazon-linux-2023-upgrade-cups-client-debuginfoamazon-linux-2023-upgrade-cups-debuginfoamazon-linux-2023-upgrade-cups-debugsourceamazon-linux-2023-upgrade-cups-develamazon-linux-2023-upgrade-cups-filesystemamazon-linux-2023-upgrade-cups-ipptoolamazon-linux-2023-upgrade-cups-ipptool-debuginfoamazon-linux-2023-upgrade-cups-libsamazon-linux-2023-upgrade-cups-libs-debuginfoamazon-linux-2023-upgrade-cups-lpdamazon-linux-2023-upgrade-cups-lpd-debuginfoamazon-linux-2023-upgrade-cups-printerappamazon-linux-2023-upgrade-cups-printerapp-debuginfo
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.