CVE-2026-34990 affects OpenPrinting CUPS 2.4.16 and earlier. A local unprivileged user can cause the cupsd scheduler to authenticate to an attacker-controlled IPP service on localhost and expose a reusable local Authorization token. The token permits localhost administrative requests. An attacker can use CUPS-Create-Local-Printer and a shared-printer setting to create a persistent file-backed printer queue despite normal FileDevice policy restrictions. Submitting a print job to that queue produces an arbitrary root file-overwrite primitive.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small standalone Python repository containing one exploit program, cups_pwn.py, plus documentation, licensing, security-policy, ignore, and dependency files. It has no third-party dependencies and uses Python standard-library modules for sockets, IPP message construction/parsing, gzip compression, threading, and subprocess execution. The exploit targets the claimed CUPS 2.4.16 local privilege-escalation issue CVE-2026-34990 / GHSA-c54j-2vqw-wpwp. It starts a loopback fake IPP service, sends CUPS-Create-Local-Printer requests to the local CUPS IPP listener, captures a Local authorization token, and reuses that token to configure a file:// device URI. It then prints a compressed sudoers document so the privileged CUPS service writes a passwordless-sudo rule. CLI options select the target username, destination sudoers path, capture port, and CUPS IPP port; the script retries printer creation and validates success with noninteractive sudo.
The repository contains a Python proof-of-concept (`CVE-2026-34990.py`) and a README. It is a standalone, non-framework local privilege-escalation exploit targeting the stated CUPS vulnerability rather than a detection-only script. The script starts a loopback IPP/HTTP listener on port 9189, submits an unauthenticated CUPS-Create-Local-Printer request to local CUPS on port 631, and parses the inbound `Authorization: Local` header to steal a reusable administrative token. It then creates a printer with a `file:///etc/sudoers.d/aporter` device URI, repeatedly promotes/enables it through token-authenticated `/admin/` IPP operations to win a race, and sends a gzip-compressed raw print job containing a sudoers rule. Successful execution writes a root-controlled sudoers fragment granting `aporter` unrestricted passwordless sudo, then attempts to delete the temporary printer. The README describes the claimed affected range as OpenPrinting CUPS 2.4.16 and earlier.
The repository contains a Python 3 proof-of-concept exploit (`CVE-2026-34990.py`) and a short README. It is a local CUPS privilege-escalation implementation rather than a scanner or a framework module. The script uses only Python standard-library modules and is intended to run as an unprivileged local user. The exploit starts a rogue IPP listener on 127.0.0.1:9189, then sends CUPS IPP Create-Local-Printer requests to the loopback cupsd service on port 631. The malicious printer's device URI points to the rogue listener. The listener initially sends an HTTP 401 Local-authentication challenge and then extracts the `Authorization: Local <token>` header when cupsd retries. With that token, the script sends authenticated administrative IPP operations to `/admin/` to create and enable a persistent raw printer whose `file://` device URI targets `/etc/sudoers.d/<user>-pwn`. Finally, it submits up to three gzip-compressed raw print jobs containing `<user> ALL=(ALL) NOPASSWD: ALL`, attempting to cause cupsd to write that sudoers fragment as root. It validates successful escalation using `sudo -n id`. The README describes the same token-disclosure, localhost callback, file-backend, and privilege-escalation flow, but the Python file contains the operational exploit logic. No external network hosts are contacted; all network activity targets loopback endpoints.
The repository consists of one standalone Python 3 exploit script and a short README. The script implements a local CUPS privilege-escalation chain: it starts a rogue loopback IPP service on TCP/9189, asks cupsd on TCP/631 to validate a printer whose device URI points to that service, answers an initial request with an HTTP Local-authentication challenge, and extracts the Local token from a retry. It then uses the token in authenticated IPP administration requests to create a persistent raw printer backed by a file:// URI targeting /etc/sudoers.d/, enables the queue, and submits gzip-compressed content that grants the current user passwordless sudo. The script finally runs `sudo -n id` to check whether escalation succeeded. It uses only Python standard-library modules, constructs IPP messages manually, has no external framework dependency, and contains a hardcoded but user-specific privilege-escalation payload.
This two-file repository contains a README and a standalone Python 3 local privilege-escalation proof of concept targeting the claimed CVE-2026-34990 in CUPS 2.4.16. The Python entry point first starts a loopback HTTP/IPP listener on port 9189, then invokes ipptool against the local CUPS service to create a temporary printer pointing to that listener. It parses the resulting outbound request for an `Authorization: Local` token. The code reuses that token against CUPS administrative IPP operations while racing creation and activation of dynamically named printer queues. It configures each queue with a `file:///etc/sudoers.d/<user>-pwn` device URI and submits a gzip-compressed raw document containing a passwordless sudo rule for the current user. It performs up to 12 queue-creation attempts and 80 administrative/print iterations per attempt, checking after each iteration whether `sudo -n id` succeeds. The code is operational exploit code rather than a scanner: it performs local socket connections and invokes an external CUPS utility, has a concrete escalation payload, and does not target remote hosts. Its hardcoded loopback endpoints and user-derived sudoers destination make it intended for execution on the local CUPS host.
This three-file repository contains a single operational Python 3 local-privilege-escalation PoC, a detailed Markdown README, and an MIT license. CVE-2026-34990.py is a standalone, standard-library-only program with IPP/HTTP request construction, a temporary loopback IPP listener, token capture logic, CUPS printer-management requests, and cleanup handling. It asks local cupsd to access an attacker-controlled IPP URI, responds with a Local-authentication challenge, captures the returned Authorization: Local token, then replays that token to CUPS administrative endpoints. The exploit uses the resulting access to configure a temporary file:// printer and submit a controlled document, aiming to make root-owned cupsd write to a selected path. Its --check mode is a non-persistent validation path that verifies the root-owned file-write primitive; normal mode uses a sudoers-file payload and sudo to obtain root command execution. The code targets only loopback CUPS and does not depend on an external exploit framework.
The repository contains a README and a standalone Python 3 proof-of-concept, poc.py, with no external dependencies beyond the standard library. It targets the claimed CVE-2026-34990 local privilege-escalation condition in CUPS <= 2.4.16. The PoC implements IPP serialization manually, starts a loopback rogue IPP server on 127.0.0.1:9189, and submits a CUPS-Create-Local-Printer request that points a device URI at that listener. The listener first returns a Local authentication challenge and records the Local authorization token when cupsd retries. It then uses the captured token for CUPS administrative operations to create a persistent raw printer whose device URI is file:///etc/sudoers.d/<user>-pwn. Finally, it submits a gzip-compressed raw IPP print job containing a NOPASSWD sudo rule and checks whether sudo -n id returns root. The README documents the intended execution flow and expected passwordless-sudo result.
This two-file repository contains a README and a standalone Python 3 exploit for the claimed CVE-2026-34990 CUPS 2.4.16 local privilege-escalation issue. `exploit.py` manually constructs IPP messages and sends them over HTTP to the local cupsd service. It starts a threaded fake IPP listener on loopback port 9189, invokes the installed `ipptool` local-printer test against it, and captures the `Authorization: Local` token supplied by CUPS. The captured token is then used for CUPS administrative operations, including creation and configuration of a local printer whose device URI is a `file://` path. The exploit submits a gzip-compressed raw print job intended to be decompressed and written by cupsd to the selected path. Its default target is a sudoers drop-in, and its hardcoded content grants user `aporter` unrestricted passwordless sudo. The script retries the printer-creation/write race up to 12 times, removes any prior target file where permitted, checks whether the target was created, verifies sudo access, and launches a root Bash shell if successful. It is an operational local exploit rather than a detection utility; its effective privilege-escalation payload is basic and hardcoded.
The repository contains a README and one Python 3 executable, cve-2026-34990.py. It is a standalone local privilege-escalation exploit/PoC for CVE-2026-34990 affecting CUPS 2.4.16, not a framework module. The script manually constructs IPP binary requests and wraps them in HTTP, communicates only with a CUPS instance on the loopback interface, and runs a local threaded token server as part of the race. It issues CUPS printer-management and print-job operations, including Create-Local-Printer, Resume-Printer, Add/Modify-Printer, Accept-Jobs, Print-Job, and Delete-Printer. The intended chain is to capture a leaked Local authorization token, use it in crafted requests, and race CUPS into writing a root-owned file. A --check path verifies the write primitive using a proof file; normal operation attempts a temporary sudoers-file write to invoke a chosen command or root shell. The code includes configurable CUPS and listener ports, proof directory, attempt count, and race iterations, and has cleanup logic for generated queues, proof artifacts, and the sudoers entry. The supplied material indicates actual exploitation capability rather than a detection-only script, although successful exploitation is timing-dependent and constrained to a vulnerable local CUPS service.
This four-file repository contains an Apache-licensed Python local privilege-escalation PoC for CVE-2026-34990 affecting CUPS 2.4.16. README.md and docs.md document the intended chain, prerequisites, race behavior, and defensive indicators; exploit.py is the sole code file and execution entry point. The script constructs raw IPP-over-HTTP requests, operates against CUPS on loopback port 631, and starts a loopback listener on port 9189. It is intended to provoke a Local authentication exchange, return a 401 WWW-Authenticate: Local challenge, capture an Authorization: Local token, and reuse that token against CUPS administration. It then performs CUPS-Create-Local-Printer and repeated CUPS-Add-Modify-Printer, CUPS-Accept-Jobs, Resume-Printer, and Print-Job operations to race a file:// device-URI primitive into writing a privileged file. The embedded sudoers payload is hard-coded for user aporter despite configurable attacker and target environment variables. A resulting file is tested via passwordless sudo before opening a root bash shell. This is not a detection-only script and contains a functional exploit design, but the supplied source omits import os while reading os.environ, making the exact submitted version fail immediately unless that import is added.
This three-file repository contains a GPLv2 license, a detailed README, and one Python 3 exploit entry point (`exploit.py`). It is a standalone, raw-socket IPP local privilege-escalation exploit rather than a Metasploit, Nuclei, or similar framework module. The code targets a locally reachable root cupsd, defaulting to 127.0.0.1:631, and starts a rogue loopback IPP service on 127.0.0.1:9189. It coerces cupsd into validating an attacker-controlled IPP printer, responds with an HTTP 401 `WWW-Authenticate: Local` challenge, and captures the Local authorization token cupsd sends on retry. The token is replayed to CUPS `/admin/` operations to create/manage a persistent `file://` printer queue, then a raw gzip-compressed `Print-Job` is sent to write controlled bytes to a filesystem path with root privileges. Its default primary outcome is a NOPASSWD sudoers fragment for the current user (or ATTACKER override), followed by `sudo -n id` verification. If that fails, it attempts a cron-based fallback that copies `/etc/shadow` to `/tmp/shadow-<user>`. Configuration is supplied through environment variables for the target/capture hosts and ports, target user, and write paths. The README claims the issue is CVE-2026-34990 affecting CUPS through 2.4.16 and fixed in 2.4.17; those version and vulnerability claims are repository-provided assertions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A moderate-severity local vulnerability addressed by the referenced Rocky Linux 9.6 security update. Successful exploitation requires low privileges and can result in high confidentiality, integrity, and availability impact; exploits are reported as available.
A moderate-severity, locally exploitable vulnerability affecting an unspecified component in AlmaLinux 9.2. The supplied CVSS v3 vector requires low privileges and indicates high impact to confidentiality, integrity, and availability; exploit code is reported as available.
Более поздняя уязвимость в экосистеме CUPS, упомянутая как пример продолжающихся архитектурных проблем; позволяет локальному непривилегированному пользователю заставить cupsd аутентифицироваться к атакующему IPP-сервису.
A CUPS vulnerability that was chained with CVE-2026-34980 to achieve unauthenticated remote code execution and root file overwrite.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.