Description
HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism.
Published: 2026-08-17
Score: 8.9 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HP Web Jetadmin (WJA) contains a vulnerability that allows an unauthenticated actor to access arbitrary files for reading or writing through a DLL hijacking mechanism. This flaw enables manipulation of files within the system that are not intended to be accessible, potentially compromising confidentiality, integrity, and availability of the host environment. The weakness is identified as a bounds-overflow or unchecked write (CWE‑787).

Affected Systems

HP Inc. Web Jetadmin is the affected product. No specific version information is provided in the data, so all installed instances of the application are considered potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.9 classifies the vulnerability as high severity, indicating significant damage potential. The EPSS score is not available, but the lack of KEV inclusion suggests that active exploitation is not yet documented. Attackers would exploit the DLL hijacking path, which requires unauthenticated access to the application, making it relatively accessible. If exploited, the attacker could create or replace critical system files, leading to privilege escalation or further compromise of the host.

Generated by OpenCVE AI on August 17, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest HP Web Jetadmin update that addresses the DLL hijacking issue.
  • Restrict write permissions to the Web Jetadmin installation directory and protect DLL files from being overridden or replaced.
  • Apply network segmentation and restrict unauthenticated access to the Web Jetadmin application, monitoring logs for unauthorized file access attempts.

Generated by OpenCVE AI on August 17, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp web Jetadmin
Vendors & Products Hp
Hp web Jetadmin

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files through a DLL hijacking mechanism.
Title HP Web Jetadmin (WJA) - Potential Arbitrary File Read/Write
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-08-17T19:30:59.137Z

Reserved: 2026-06-17T19:56:33.403Z

Link: CVE-2026-12553

cve-icon Vulnrichment

Updated: 2026-08-17T19:30:53.660Z

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:24.560

Modified: 2026-08-17T20:16:39.493

Link: CVE-2026-12553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:00:04Z

Weaknesses