Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34990-poc — Python PoC reproducing the CUPS 2.4.16 local-printer flaw: captures the Local auth token via a rogue IPP endpoint, creates a file:// printer, and races a job to write root-owned files. | Kitploit
Tools/GitHubGitHub/0xc4rc3l/cve-2026-34990-poc
Defensive ToolsPrivilege EscalationVulnerability AnalysisExploitationPenetration Testing
GitHub0xc4rc3l/cve-2026-34990-poc

CVE-2026-34990-poc

Python PoC reproducing the CUPS 2.4.16 local-printer flaw: captures the Local auth token via a rogue IPP endpoint, creates a file:// printer, and races a job to write root-owned files.

View Repository
13 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34990 — CUPS Local-Printer PoC

Authorized testing / research use only. Run this PoC only against systems you own or are explicitly authorized to test.

This repository contains a system-CUPS-oriented reproduction of the local-printer vulnerability in CUPS 2.4.16.

The implementation was developed from the published CUPS vulnerability reproduction and adapted to work against an already-running system CUPS installation, rather than requiring a separately installed CUPS build and a root-run reproduction harness.

What this PoC demonstrates

The reproduction follows this general chain:

CUPS 2.4.16
    │
    ▼
Local authentication challenge
    │
    ▼
Attacker-controlled IPP endpoint
    │
    ▼
Authorization: Local <token>
    │
    ▼
Authenticated CUPS administration
    │
    ▼
CUPS-Create-Local-Printer
    │
    ▼
file:// device URI
    │
    ▼
Printer/job race
    │
    ▼
Root-owned target file

The exploit is race-dependent, so successful execution is not guaranteed on every attempt.

Why this implementation exists

The published reproduction is designed as a controlled vulnerability harness. In particular, it assumes a dedicated CUPS installation and performs setup/reset operations that are appropriate for a reproduction environment but are not representative of an already-running distribution installation.

This implementation instead:

  • Uses the system's existing CUPS service.
  • Uses the installed ipptool binary.
  • Uses the system cups-create-local-printer.test definition when available.
  • Captures the CUPS Local authorization token.
  • Reuses that token for authenticated IPP administration.
  • Reproduces the local-printer / file:// primitive.
  • Performs the printer/job sequence used by the reproduction.
  • Treats the final privilege check as the success condition.

Requirements

Tested in the author's lab with:

  • CUPS 2.4.16
  • Python 3
  • ipptool

The test definition is expected at:

/usr/share/cups/ipptool/cups-create-local-printer.test

Check your installation with:

cupsd -v
which ipptool
find /usr/share/cups -name 'cups-create-local-printer.test' 2>/dev/null

Usage

Configure the attacker identity and target path through environment variables:

export CUPS_ATTACKER="$USER"
export CUPS_TARGET="/tmp/cups-poc-target"
python3 exploit.py

For a controlled privilege-escalation reproduction, choose a target appropriate to your isolated test environment.

The script also defaults to a sudoers-style target under /etc/sudoers.d/, so do not run it casually on a production system.

Important implementation details

Local-token disclosure

The PoC starts an IPP listener and causes CUPS to authenticate against it. The listener initially returns a 401 challenge with:

WWW-Authenticate: Local trc="y"

The subsequent request contains:

Authorization: Local <token>

The token is then reused against the local CUPS administration endpoint.

Local printer creation

The reproduction uses:

CUPS-Create-Local-Printer

with a file:// device URI.

Race / job sequence

The candidate loop performs the printer operations repeatedly, including:

CUPS-Add-Modify-Printer
CUPS-Accept-Jobs
Resume-Printer
Print-Job

The race is intentionally repeated because a single attempt may not win.

Relationship to the published reproduction

This repository is an adaptation, not the canonical upstream implementation.

The request-building logic and exploitation sequence are based on the published reproduction. The main changes are around running against an existing system CUPS installation and removing reproduction-environment setup/reset assumptions.

See the upstream OpenPrinting CUPS security advisory and repository for the authoritative vulnerability information and original reproduction.

Limitations

  • The exploit is race-dependent.
  • Distribution-specific CUPS configuration may affect behavior.
  • File permissions and AppArmor/other confinement can change the result.
  • A successful token disclosure does not by itself imply successful privilege escalation.
  • The PoC has only been validated in the author's controlled lab environment.

Responsible use

Do not use this against CUPS installations without authorization.

For defensive validation, the useful indicators include unexpected IPP requests to attacker-controlled endpoints, unusual Local authentication exchanges, creation of unexpected local printers, and suspicious printer/job activity.

Download Tool