Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34990-poc — CVE-2026-34990 — CUPS <= 2.4.16 Local Privilege Escalation | Kitploit
Tools/GitHubGitHub/bara-almustafa/cve-2026-34990-poc
Defensive ToolsPrivilege EscalationVulnerability AnalysisExploitationSecurity VirtualizationPenetration TestingLearning & Education
GitHubbara-almustafa/cve-2026-34990-poc

CVE-2026-34990-poc

CVE-2026-34990 — CUPS <= 2.4.16 Local Privilege Escalation

View Repository
2 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34990 — CUPS <= 2.4.16 Local Privilege Escalation

Local unprivileged user → root, via a leaked CUPS Local authorization token and a policy-bypassing file:/// print queue.

PoC by 0xcybersoldier

status platform language type CVE


Table of Contents

  • Overview
  • Vulnerability Details
  • Affected Versions
  • Attack Chain
  • Requirements
  • Installation
  • Usage
  • Example Run
  • How It Works Internally
  • Troubleshooting
  • Detection
  • Mitigation
  • References
  • Disclaimer
  • Author

Overview

CVE-2026-34990 is a local privilege escalation flaw in OpenPrinting CUPS affecting versions 2.4.16 and earlier.

A local unprivileged user who can reach the CUPS daemon (cupsd) can potentially cause it to authenticate against an attacker-controlled IPP service on the loopback interface.

The resulting Authorization: Local <token> credential can then be reused against the CUPS administrative interface.

The attack chain can ultimately be used to create a file:/// print queue and cause cupsd to write an attacker-controlled file with root privileges.

The canonical demonstration uses a sudoers drop-in to obtain a root shell.

This repository contains a single-file Python 3 PoC implementing the attack chain, including a safer --check mode for demonstrating the vulnerable file-write behavior without directly creating a persistent privilege-escalation configuration.


Vulnerability Details

FieldValue
CVE IDCVE-2026-34990
ComponentOpenPrinting CUPS (cupsd)
Affected Versions<= 2.4.16
Vulnerability ClassCWE-306 / CWE-284
ImpactLocal Privilege Escalation
Attack VectorLocal
Privileges RequiredLow
User InteractionNone
Discovered ByAsim Viladi Oglu Manizada
AdvisoryGHSA-c54j-2vqw-wpwp

Affected Versions

The PoC targets:

OpenPrinting CUPS <= 2.4.16

Check the locally running CUPS version:

curl -sI http://127.0.0.1:631 | grep -i '^Server:'

Example:

Server: CUPS/2.4.16 IPP/2.1

Note: Verify the current upstream advisory before relying on the affected-version range in production research, as vendor patches and version status may change.


Attack Chain

 [1] Local user issues CUPS-Create-Local-Printer
         |
         | device-uri = ipp://127.0.0.1:9189/ipp/print
         v
 [2] cupsd connects to the attacker-controlled
     IPP service on loopback
         |
         v
 [3] Fake IPP service responds with:
     401 Unauthorized
     WWW-Authenticate: Local trc="y"
         |
         v
 [4] CUPS/libcups retries the request with:
     Authorization: Local <token>
         |
         v
 [5] Token captured
         |
         v
 [6] Token reused against the CUPS administrative interface
         |
         v
 [7] Temporary file:// printer is created and
     transitioned through the printer-management workflow
         |
         v
 [8] Print-Job causes cupsd to write the supplied
     document to the file:// target
         |
         v
 [9] Demonstration payload can modify a privileged
     configuration such as sudoers
         |
         v
       ROOT

Requirements

  • Python 3.8+
  • Standard Python library only
  • Local shell access as an unprivileged user
  • Reachable CUPS service on 127.0.0.1:631
  • sudo available for the privilege-escalation demonstration
  • A Linux system running a vulnerable CUPS version

No external Python packages are required.


Installation

Clone the repository:

git clone https://github.com/bara-almustafa/CVE-2026-34990-poc.git
cd CVE-2026-34990-poc

Make the PoC executable:

chmod +x cve-2026-34990.py

No additional dependencies are required.


Usage

Safe Check Mode

Start with the non-persistent verification mode:

./cve-2026-34990.py --check

The check mode attempts to demonstrate the vulnerable root-owned file-write primitive using a temporary proof file and cleans up after the test.


Root Shell Demonstration

The default mode demonstrates the complete privilege-escalation chain:

./cve-2026-34990.py

Execute a Command as Root

A command can be supplied with:

./cve-2026-34990.py -c 'id'

Example:

./cve-2026-34990.py -c 'id; whoami'

Options

FlagDefaultDescription
--cups-port631Local CUPS TCP port
--listen-port9189Loopback port used by the token-capture listener
--checkOffSafe verification mode
-c, --command—Execute a command after successful exploitation
--proof-dir/var/tmpParent directory for temporary proof files
--attempts8Number of file-write attempts
--iterations80Number of IPP request rounds per attempt

Example Run

$ ./cve-2026-34990.py --check

 ██████╗ ██╗  ██╗ ██████╗██╗   ██╗██████╗ ███████╗██████╗ ███████╗ ██████╗ ██╗     ██████╗ ██╗███████╗██████╗
██╔═████╗╚██╗██╔╝██╔════╝╚██╗ ██╔╝██╔══██╗██╔════╝██╔══██╗██╔════╝██╔═══██╗██║     ██╔══██╗██║██╔════╝██╔══██╗
██║██╔██║ ╚███╔╝ ██║      ╚████╔╝ ██████╔╝███████╗██████╔╝█████╗  ██║   ██║██║     ██║  ██║██║█████╗  ██████╔╝
████╔╝██║ ██╔██╗ ██║       ╚██╔╝  ██╔══██╗╚════██║██╔══██╗██╔══╝  ██║   ██║██║     ██║  ██║██║██╔══╝  ██╔══██╗
╚██████╔╝██╔╝ ██╗╚██████╗   ██║   ██████╔╝███████║██║  ██║███████╗╚██████╔╝███████╗██████╔╝██║███████╗██║  ██║
 ╚═════╝ ╚═╝  ╚═╝ ╚═════╝   ╚═╝   ╚═════╝ ╚══════╝╚═╝  ╚═╝╚══════╝ ╚═════╝ ╚══════╝╚═════╝ ╚═╝╚══════╝╚═╝  ╚═╝

  CVE-2026-34990 :: CUPS <= 2.4.16 Local Privilege Escalation
  PoC by 0xcybersoldier

[*] Triggering CUPS token leak...
[+] Captured CUPS Local authorization token
[*] File-write race: attempt 1/8
[+] VULNERABLE: CUPS wrote a root-owned proof file

How It Works Internally

1. Token Capture

The PoC creates a temporary CUPS printer whose device-uri points toward an attacker-controlled IPP listener on the loopback interface.

Example:

ipp://127.0.0.1:9189/ipp/print

The local listener responds with an authentication challenge:

401 Unauthorized
WWW-Authenticate: Local trc="y"

This causes the CUPS client/server interaction to retry using the local authentication mechanism.

The PoC captures the resulting:

Authorization: Local <token>

credential.


2. Administrative Access

The captured token is reused in requests to the CUPS administrative interface.

Conceptually:

Authorization: Local <TOKEN>

This provides the authorization context required for subsequent printer-management operations.


3. Printer Creation

The attack then abuses the printer-management workflow to create a queue referencing a file:// target.

The relevant target has the form:

Download Tool