Description
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Published: 2026-09-22
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in HP Support Assistant versions older than 9.55.10.0 permits a local attacker to gain higher privileges on a machine by exploiting insufficient access controls. The flaw is a classic improper authorization issue (CWE‑269) that could allow an attacker who has local login rights to execute privileged operations or modify system configuration, potentially compromising the confidentiality, integrity, or availability of the affected system.

Affected Systems

The affected product is HP Support Assistant from HP Inc. All installations running any version earlier than 9.55.10.0 are susceptible.

Risk and Exploitability

The CVSS score of 7.3 classifies this as a high‑severity vulnerability. No EPSS data is available, so the exploitation likelihood remains unclear, and the vulnerability has not been listed in the CISA KEV catalog. The attack requires local access, which is inferred because the description mentions a local attacker; no remote exploit mechanism is cited.

Generated by OpenCVE AI on September 22, 2026 at 16:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the HP Support Assistant to version 9.55.10.0 or newer as issued by HP
  • Restrict local account privileges on systems running the vulnerable software—deny unnecessary administrative rights
  • Monitor for any anomalous privilege changes or unauthorized execution of elevated processes on affected machines

Generated by OpenCVE AI on September 22, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp Inc.
Hp Inc. hp Support Assistant
Vendors & Products Hp Inc.
Hp Inc. hp Support Assistant

Tue, 22 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Title HP Support Assistant - Local Escalation of Privilege
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Inc. Hp Support Assistant
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-22T14:57:28.834Z

Reserved: 2026-08-14T21:39:59.428Z

Link: CVE-2026-19915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T15:17:09.750

Modified: 2026-09-22T15:17:09.750

Link: CVE-2026-19915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T16:30:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management