
CVE-2026-34990 — CUPS <= 2.4.16 Local Privilege Escalation
Local unprivileged user → root, via a leaked CUPS
Localauthorization token and a policy-bypassingfile:///print queue.PoC by 0xcybersoldier
CVE-2026-34990 is a local privilege escalation flaw in OpenPrinting CUPS affecting versions 2.4.16 and earlier.
A local unprivileged user who can reach the CUPS daemon (cupsd) can potentially cause it to authenticate against an attacker-controlled IPP service on the loopback interface.
The resulting Authorization: Local <token> credential can then be reused against the CUPS administrative interface.
The attack chain can ultimately be used to create a file:/// print queue and cause cupsd to write an attacker-controlled file with root privileges.
The canonical demonstration uses a sudoers drop-in to obtain a root shell.
This repository contains a single-file Python 3 PoC implementing the attack chain, including a safer --check mode for demonstrating the vulnerable file-write behavior without directly creating a persistent privilege-escalation configuration.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-34990 |
| Component | OpenPrinting CUPS (cupsd) |
| Affected Versions | <= 2.4.16 |
| Vulnerability Class | CWE-306 / CWE-284 |
| Impact | Local Privilege Escalation |
| Attack Vector | Local |
| Privileges Required | Low |
| User Interaction | None |
| Discovered By | Asim Viladi Oglu Manizada |
| Advisory | GHSA-c54j-2vqw-wpwp |
The PoC targets:
OpenPrinting CUPS <= 2.4.16
Check the locally running CUPS version:
curl -sI http://127.0.0.1:631 | grep -i '^Server:'
Example:
Server: CUPS/2.4.16 IPP/2.1
Note: Verify the current upstream advisory before relying on the affected-version range in production research, as vendor patches and version status may change.
[1] Local user issues CUPS-Create-Local-Printer
|
| device-uri = ipp://127.0.0.1:9189/ipp/print
v
[2] cupsd connects to the attacker-controlled
IPP service on loopback
|
v
[3] Fake IPP service responds with:
401 Unauthorized
WWW-Authenticate: Local trc="y"
|
v
[4] CUPS/libcups retries the request with:
Authorization: Local <token>
|
v
[5] Token captured
|
v
[6] Token reused against the CUPS administrative interface
|
v
[7] Temporary file:// printer is created and
transitioned through the printer-management workflow
|
v
[8] Print-Job causes cupsd to write the supplied
document to the file:// target
|
v
[9] Demonstration payload can modify a privileged
configuration such as sudoers
|
v
ROOT
127.0.0.1:631sudo available for the privilege-escalation demonstrationNo external Python packages are required.
Clone the repository:
git clone https://github.com/bara-almustafa/CVE-2026-34990-poc.git
cd CVE-2026-34990-poc
Make the PoC executable:
chmod +x cve-2026-34990.py
No additional dependencies are required.
Start with the non-persistent verification mode:
./cve-2026-34990.py --check
The check mode attempts to demonstrate the vulnerable root-owned file-write primitive using a temporary proof file and cleans up after the test.
The default mode demonstrates the complete privilege-escalation chain:
./cve-2026-34990.py
A command can be supplied with:
./cve-2026-34990.py -c 'id'
Example:
./cve-2026-34990.py -c 'id; whoami'
| Flag | Default | Description |
|---|---|---|
--cups-port | 631 | Local CUPS TCP port |
--listen-port | 9189 | Loopback port used by the token-capture listener |
--check | Off | Safe verification mode |
-c, --command | — | Execute a command after successful exploitation |
--proof-dir | /var/tmp | Parent directory for temporary proof files |
--attempts | 8 | Number of file-write attempts |
--iterations | 80 | Number of IPP request rounds per attempt |
$ ./cve-2026-34990.py --check
██████╗ ██╗ ██╗ ██████╗██╗ ██╗██████╗ ███████╗██████╗ ███████╗ ██████╗ ██╗ ██████╗ ██╗███████╗██████╗
██╔═████╗╚██╗██╔╝██╔════╝╚██╗ ██╔╝██╔══██╗██╔════╝██╔══██╗██╔════╝██╔═══██╗██║ ██╔══██╗██║██╔════╝██╔══██╗
██║██╔██║ ╚███╔╝ ██║ ╚████╔╝ ██████╔╝███████╗██████╔╝█████╗ ██║ ██║██║ ██║ ██║██║█████╗ ██████╔╝
████╔╝██║ ██╔██╗ ██║ ╚██╔╝ ██╔══██╗╚════██║██╔══██╗██╔══╝ ██║ ██║██║ ██║ ██║██║██╔══╝ ██╔══██╗
╚██████╔╝██╔╝ ██╗╚██████╗ ██║ ██████╔╝███████║██║ ██║███████╗╚██████╔╝███████╗██████╔╝██║███████╗██║ ██║
╚═════╝ ╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝╚══════╝ ╚═════╝ ╚══════╝╚═════╝ ╚═╝╚══════╝╚═╝ ╚═╝
CVE-2026-34990 :: CUPS <= 2.4.16 Local Privilege Escalation
PoC by 0xcybersoldier
[*] Triggering CUPS token leak...
[+] Captured CUPS Local authorization token
[*] File-write race: attempt 1/8
[+] VULNERABLE: CUPS wrote a root-owned proof file
The PoC creates a temporary CUPS printer whose device-uri points toward an attacker-controlled IPP listener on the loopback interface.
Example:
ipp://127.0.0.1:9189/ipp/print
The local listener responds with an authentication challenge:
401 Unauthorized
WWW-Authenticate: Local trc="y"
This causes the CUPS client/server interaction to retry using the local authentication mechanism.
The PoC captures the resulting:
Authorization: Local <token>
credential.
The captured token is reused in requests to the CUPS administrative interface.
Conceptually:
Authorization: Local <TOKEN>
This provides the authorization context required for subsequent printer-management operations.
The attack then abuses the printer-management workflow to create a queue referencing a file:// target.
The relevant target has the form: