Description
A potential security vulnerability has been identified in the HP Support
Assistant for versions prior to 9.53.2.0. The vulnerability
could potentially allow a local attacker to escalate
privileges due to insufficient access controls.
Published: 2026-09-03
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker can leverage insufficient access controls in HP Support Assistant versions before 9.53.2.0 to increase privileges. This flaw can grant a user higher authority within the local system, potentially allowing them to execute restricted operations or manipulate system resources, thereby impacting confidentiality, integrity, and availability of the host.

Affected Systems

HP Inc. HP Support Assistant is affected, specifically all releases older than 9.53.2.0. No specific hardware models are specified, so the issue applies broadly to all environments running the vulnerable version of the application.

Risk and Exploitability

The CVSS score of 7.3 indicates a high risk for a local attacker. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability is listed outside the CISA KEV catalog. Based on the description, the attack vector is local; a threat actor must have physical or local administrative access to the machine. The user does not need to bypass any network controls, but must be able to run applications with the user’s rights.

Generated by OpenCVE AI on September 3, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HP Support Assistant to version 9.53.2.0 or later where the access control issue is resolved.
  • For environments where an upgrade is delayed, apply least‑privilege policies to all local user accounts: remove unnecessary administrative rights and restrict the use of the application to users who genuinely need it.
  • If possible, isolate the application on a separate account or sandbox that limits its ability to modify critical system files and settings until a patch can be applied.

Generated by OpenCVE AI on September 3, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp support Assistant
Vendors & Products Hp
Hp support Assistant

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Title HP Support Assistant – Potential Escalation of Privilege
First Time appeared Hp Inc.
Hp Inc. hp Support Assistant
Weaknesses CWE-1220
CPEs cpe:2.3:a:hp_inc.:hp_support_assistant:*:*:*:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Support Assistant
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Support Assistant
Hp Inc. Hp Support Assistant
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-03T18:29:22.769Z

Reserved: 2026-07-10T17:06:44.267Z

Link: CVE-2026-15431

cve-icon Vulnrichment

Updated: 2026-09-03T18:29:18.891Z

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:26.820

Modified: 2026-09-03T19:17:26.820

Link: CVE-2026-15431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:30:10Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control