Description
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Published: 2026-08-31
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker can potentially raise their privileges on a system running HP ImageDiags versions before 5.0.0.36. The flaw stems from insufficient access controls that fail to restrict privileged actions to authorized users, allowing an attacker with local access to exploit the software and gain elevated rights. This weakness can lead to unauthorized system changes, data theft, or further lateral movement within the organization. It is classified as a CWE-379 vulnerability.

Affected Systems

HP ImageDiags from HP Inc. is affected. All releases earlier than version 5.0.0.36 lack the fix. Users should confirm that their environment runs at least 5.0.0.36 or a later updated release.

Risk and Exploitability

The CVSS score of 7 indicates a high impact and medium likelihood of exploitation. The EPSS score is not available, so the exact probability is uncertain, but the absence of a KEV listing suggests that no widespread attacks have been observed yet. The attack vector is local, meaning an attacker must already have some form of access or presence on the target machine. Under those conditions, the flaw can be leveraged to gain privileged system access.

Generated by OpenCVE AI on August 31, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HP ImageDiags to version 5.0.0.36 or newer, ensuring the vulnerability is patched.
  • Configure the application to enforce strict access control checks, verifying that only authorized accounts can perform privileged operations.
  • Limit local user accounts that can run or access HP ImageDiags, applying least‑privilege principles; if a patch is not yet available, consider disabling the component or restricting its use to a minimal subset of users.

Generated by OpenCVE AI on August 31, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Title HP ImageDiags - Potential Escalation of Privilege
Weaknesses CWE-379
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-08-31T20:53:49.878Z

Reserved: 2026-08-28T16:42:02.512Z

Link: CVE-2026-82346

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:53.853

Modified: 2026-08-31T21:17:53.853

Link: CVE-2026-82346

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-379

    Creation of Temporary File in Directory with Insecure Permissions