CVE-2022-26691
published 2022-05-26CVE-2022-26691: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur…
PriorityP429medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.58%
43.8th percentile
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | < 499.4 | 499.4 |
| apple | cups | >= 0 < 2.3.3op2-3+deb11u2 | 2.3.3op2-3+deb11u2 |
| apple | cups | >= 0 < 2.4.2-1 | 2.4.2-1 |
| apple | cups | >= 0 < 2.4.2-1 | 2.4.2-1 |
| apple | cups | >= 0 < 2.4.2-1 | 2.4.2-1 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.9 | 2.2.7-1ubuntu2.9 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.2 | 2.3.1-9ubuntu1.2 |
| apple | cups | >= 0 < 2.4.1op1-1ubuntu4.1 | 2.4.1op1-1ubuntu4.1 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11+esm1 | 2.1.3-4ubuntu0.11+esm1 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | < 12.3 | 12.3 |
| apple | macos | >= 11.0 < 11.6.5 | 11.6.5 |
| apple | macos | >= unspecified < 12.3 | 12.3 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 2022 | 2022 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-003_catalina | — | — |
| debian | cups | < cups 2.4.2-1 (bookworm) | cups 2.4.2-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_oracle9.8CRITICAL
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cups vulnerabilities
osv·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] cups vulnerabilities
cups vulnerabilities
USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
OSV
cups vulnerabilities
osv·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] cups vulnerabilities
cups vulnerabilities
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
GHSA
GHSA-h495-hfpg-xw55: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-27
CVE-2022-26691 [HIGH] CWE-269 GHSA-h495-hfpg-xw55: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
OSV
CVE-2022-26691: A logic issue was addressed with improved state management
osv·2022-05-26·CVSS 6.7
CVE-2022-26691 [MEDIUM] CVE-2022-26691: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2022-05-31·CVSS 3.3
CVE-2020-10001 [LOW] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, CVE-2020-10001)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
CUPS vulnerabilities
vendor_ubuntu·2022-05-31·CVSS 3.3
CVE-2022-26691 [LOW] CUPS vulnerabilities
Title: CUPS vulnerabilities
Summary: Several security issues were fixed in CUPS.
USN-5454-1 fixed several vulnerabilities in CUPS. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Joshua Mason discovered that CUPS incorrectly handled the secret key used
to access the administrative web interface. A remote attacker could
possibly use this issue to open a session as an administrator and execute
arbitrary code. (CVE-2022-26691)
It was discovered that CUPS incorrectly handled certain memory operations
when handling IPP printing. A remote attacker could possibly use this issue
to cause CUPS to crash, leading to a denial of service, or obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2019-8842, C
Red Hat
cups: authorization bypass when using "local" authorization
vendor_redhat·2022-05-25·CVSS 6.7
CVE-2022-26691 [MEDIUM] CWE-288 cups: authorization bypass when using "local" authorization
cups: authorization bypass when using "local" authorization
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
An authorization vulnerability was found in the CUPS printing system. This security vulnerability occurs when local authorization happens. This flaw allows an attacker to authenticate to CUPS as root/admin without the 32-byte secret key and perform arbitrary code execution.
Mitigation: Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Package: cups (Red Hat Enterprise Linux 6) -
Microsoft
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina macOS Monterey 12.3 macOS Big Sur 11.6.5. An application may be able to gain elevat
vendor_msrc·2022-05-10·CVSS 6.7
CVE-2022-26691 [MEDIUM] CWE-697 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina macOS Monterey 12.3 macOS Big Sur 11.6.5. An application may be able to gain elevat
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina macOS Monterey 12.3 macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we w
Apple
CVE-2022-26691: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 6.7
CVE-2022-26691 [MEDIUM] CVE-2022-26691: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-26691
Component: CUPS
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-26691: macOS Big Sur 11.6.5
vendor_apple·2022-03-14·CVSS 6.7
CVE-2022-26691 [MEDIUM] CVE-2022-26691: macOS Big Sur 11.6.5
Apple Security Update: About the security content of macOS Big Sur 11.6.5
Product: macOS Big Sur
Version: 11.6.5
CVE: CVE-2022-26691
Component: CUPS
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state management.
Apple
CVE-2022-26691: Security Update 2022-003 Catalina
vendor_apple·2022-03-14·CVSS 6.7
CVE-2022-26691 [MEDIUM] CVE-2022-26691: Security Update 2022-003 Catalina
Apple Security Update: About the security content of Security Update 2022-003 Catalina
Product: Security Update 2022-003 Catalina
CVE: CVE-2022-26691
Component: CUPS
Impact: An application may be able to gain elevated privileges
Description: A logic issue was addressed with improved state management.
Oracle
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2021-26691
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2021-26691 [CRITICAL] Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) — CVE-2021-26691
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (Apache HTTP Server) vulnerability
CVE: CVE-2021-26691
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Debian
CVE-2022-26691: cups - A logic issue was addressed with improved state management. This issue is fixed ...
vendor_debian·2022·CVSS 6.7
CVE-2022-26691 [MEDIUM] CVE-2022-26691: cups - A logic issue was addressed with improved state management. This issue is fixed ...
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
Scope: local
bookworm: resolved (fixed in 2.4.2-1)
bullseye: resolved (fixed in 2.3.3op2-3+deb11u2)
forky: resolved (fixed in 2.4.2-1)
sid: resolved (fixed in 2.4.2-1)
trixie: resolved (fixed in 2.4.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/OpenPrinting/cups/commit/de4f8c196106033e4c372dce3e91b9d42b0b9444https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0026/MNDT-2022-0026.mdhttps://lists.debian.org/debian-lts-announce/2022/05/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQ6TD7F3VRITPEHFDHZHK7MU6FEBMZ5U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQRIT4H75XV6M42K7ZTARWZ7YLLYQHPO/https://support.apple.com/en-us/HT213183https://support.apple.com/en-us/HT213184https://support.apple.com/en-us/HT213185https://www.debian.org/security/2022/dsa-5149https://github.com/OpenPrinting/cups/commit/de4f8c196106033e4c372dce3e91b9d42b0b9444https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0026/MNDT-2022-0026.mdhttps://lists.debian.org/debian-lts-announce/2022/05/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQ6TD7F3VRITPEHFDHZHK7MU6FEBMZ5U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YQRIT4H75XV6M42K7ZTARWZ7YLLYQHPO/https://support.apple.com/en-us/HT213183https://support.apple.com/en-us/HT213184https://support.apple.com/en-us/HT213185https://www.debian.org/security/2022/dsa-5149
2022-05-26
Published