Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34990-poc — Proof-of-concept exploit for CVE-2026-34990, a CUPS 2.4.16 local privilege escalation via arbitrary file write through CUPS_CREATE_LOCAL_PRINTER and a captured local auth token. | Kitploit
Tools/GitHubGitHub/khush-613/cve-2026-34990-poc
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubkhush-613/cve-2026-34990-poc

CVE-2026-34990-poc

Proof-of-concept exploit for CVE-2026-34990, a CUPS 2.4.16 local privilege escalation via arbitrary file write through CUPS_CREATE_LOCAL_PRINTER and a captured local auth token.

View Repository
223 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34990

CUPS 2.4.16 local privilege escalation via arbitrary file write through CUPS_CREATE_LOCAL_PRINTER.

Vulnerability

CUPS allows creating local printers with a device-uri set to a file:// path. Submitting a print job with document-format: application/vnd.cups-raw and compression: gzip causes cupsd to decompress the job data and write it directly to that path — as whatever user cupsd runs as (typically root or a highly-privileged service account).

The local auth token required for admin operations can be captured by pointing ipptool's cups-create-local-printer.test at a fake IPP server on localhost. When CUPS connects to authenticate, it sends the Authorization: Local <token> header, which you intercept before CUPS can verify it.

How it works

  1. Start a fake IPP server on localhost:9189
  2. Run ipptool with cups-create-local-printer.test pointed at the fake server — CUPS sends its local auth token to authenticate
  3. Reply with 401 WWW-Authenticate: Local trc="y" on the first connection to capture the token cleanly
  4. Use the token to create a printer with device-uri: file:///etc/sudoers.d/<user>-pwn
  5. Configure the printer (add/modify, accept-jobs, resume) and submit a gzipped sudoers entry as the print job
  6. CUPS decompresses the job data and writes it to the target path
  7. sudo -n /bin/bash

The create_local_printer call keeps its socket open during the race — this holds the printer registration in-flight while the admin ops and print job land.

Requirements

  • CUPS 2.4.16 running on localhost:631
  • ipptool installed with cups-create-local-printer.test (standard CUPS install)
  • cupsd running with write access to the target path
  • Python 3.8+

Usage

# writes /etc/sudoers.d/<your-username>-pwn by default
python3 exploit.py

# custom target
CUPS_TARGET=/etc/sudoers.d/youruser-pwn CUPS_ATTACKER=youruser python3 exploit.py

Edit SUDOERS_LINE in the script to use your actual username — the default is aporter.

The exploit tries up to 12 times. Each attempt deletes and recreates the printer to reset state.

Tested on

  • Ubuntu 24.04, CUPS 2.4.16

Disclaimer

For authorized security testing and research only.

Download Tool