Description
A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability.
Published: 2026-06-24
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the HP Accessory WMI Provider installer for certain HP Docking Stations could allow an attacker to elevate privileges or execute arbitrary code. The weakness originates from the installer component, which if exploited, can grant the attacker higher-level permissions on the target system. This could lead to unauthorized access, data theft or further compromise of the environment.

Affected Systems

The affected products are HP Dock Accessory devices supplied by HP Inc., specifically docking stations that use the WMI Provider installer. All models identified by HP as having the vulnerable installer should be reviewed and updated. No version range is specified in the advisory, so all current installations should be considered potentially vulnerable until the update is applied.

Risk and Exploitability

The CVSS base score is 7.3, indicating a high risk level. EPSS data is not available, so the exact exploitation likelihood cannot be quantified, but the lack of an EPSS score does not imply low risk. The vulnerability is not listed in the CISA KEV catalog, yet the nature of the flaw—privilege escalation and arbitrary code execution—means it can be serious if locally or remotely triggered. Attackers would need to deliver or trigger the flawed installer, most likely through local execution or if the installer is exposed to untrusted inputs. The absence of explicit remote vector information suggests that the threat surface is primarily local, but the possible consequence of code execution warrants urgent remediation.

Generated by OpenCVE AI on June 24, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HP-released software update to all HP Docking Stations that use the WMI Provider installer.
  • Configure operating‑system permissions so that only trusted administrators can run installer executables.
  • Enable detailed logging for WMI Provider installation events and review logs for unexpected activity.

Generated by OpenCVE AI on June 24, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability.
Title HP Dock Accessory WMI Provider Installer Security Update
Weaknesses CWE-379
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-06-24T19:47:15.371Z

Reserved: 2026-04-30T18:32:09.603Z

Link: CVE-2026-7539

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T21:45:15Z

Weaknesses
  • CWE-379

    Creation of Temporary File in Directory with Insecure Permissions