
Proof-of-concept exploit for CVE-2026-34990, a CUPS 2.4.16 local privilege escalation via arbitrary file write through CUPS_CREATE_LOCAL_PRINTER and a captured local auth token.
CUPS 2.4.16 local privilege escalation via arbitrary file write through CUPS_CREATE_LOCAL_PRINTER.
CUPS allows creating local printers with a device-uri set to a file:// path. Submitting a print job with document-format: application/vnd.cups-raw and compression: gzip causes cupsd to decompress the job data and write it directly to that path — as whatever user cupsd runs as (typically root or a highly-privileged service account).
The local auth token required for admin operations can be captured by pointing ipptool's cups-create-local-printer.test at a fake IPP server on localhost. When CUPS connects to authenticate, it sends the Authorization: Local <token> header, which you intercept before CUPS can verify it.
ipptool with cups-create-local-printer.test pointed at the fake server — CUPS sends its local auth token to authenticate401 WWW-Authenticate: Local trc="y" on the first connection to capture the token cleanlydevice-uri: file:///etc/sudoers.d/<user>-pwnsudo -n /bin/bashThe create_local_printer call keeps its socket open during the race — this holds the printer registration in-flight while the admin ops and print job land.
ipptool installed with cups-create-local-printer.test (standard CUPS install)# writes /etc/sudoers.d/<your-username>-pwn by default
python3 exploit.py
# custom target
CUPS_TARGET=/etc/sudoers.d/youruser-pwn CUPS_ATTACKER=youruser python3 exploit.py
Edit SUDOERS_LINE in the script to use your actual username — the default is aporter.
The exploit tries up to 12 times. Each attempt deletes and recreates the printer to reset state.
For authorized security testing and research only.