
LPE PoC for CVE-2026-34990 using a CUPS root file write vulnerability.
A Python3 adaptation of the original CUPS disclosure and PoC that runs as an ordinary local user against an existing CUPS service. It demonstrates a leaked Authorization: Local token and a race that lets CUPS write a file as root.
python3 cve-2026-34990.py --check # Test for a root-owned file write
python3 cve-2026-34990.py # Open a root shell
python3 cve-2026-34990.py -c 'id' # Run one command as root
Successful execution temporarily creates a sudoers entry, runs the requested action, and attempts to remove the entry and queues afterward.
Optional flags include --cups-port, --listen-port, --proof-dir, --attempts, and --iterations; see --help.
Vulnerability discovery, original research, and original PoC: Asim Viladi Oglu Manizada (@manizada), as documented in the OpenPrinting security advisory.
This repository's script adapts the published attack to run without root setup on an existing CUPS installation, adds a non-persistent proof mode, and attempts cleanup.