CVE-2026-34990-CUPS-LPE-PoC
Author
Noorkhalel
Published
2026-09-28
Stars
1
Forks
0
Repository
Description
Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite.
CVE-CVE-2026-34990 Details
Severity
HIGH
CVSS Score
7.8
CWE
CWE-287
Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice p...
Related PoCs for CVE-2026-34990
CVE-2026-34990...
0
predyy
cve-2026-34990-POC...
0
offesivezapper