System running
Last check: 2026-09-29 00:26:08 | Auto-updates every hour
754 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

cve-2026-34990-POC

CVE-2026-34990 Information Disclosure Python #poc #github #cve-2026-34990 #informationdisclosure
Author
offesivezapper
Published
2026-09-28
Stars
0
Forks
0
Description

Technical analysis and proof-of-concept research for CVE-2026-34990, a local privilege-escalation vulnerability affecting CUPS. This repository documents the vulnerability mechanics, CUPS/IPP request flow, authentication-token disclosure, the localhost callback technique, and the subsequent privilege-escalation primitive.

CVE-CVE-2026-34990 Details
Severity
HIGH
CVSS Score
7.8
CWE
CWE-287
Description

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice p...

Related PoCs for CVE-2026-34990
CVE-2026-34990-CUPS-LPE-PoC...
1 Noorkhalel
CVE-2026-34990...
0 predyy
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources