Description
The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released
to mitigate this potential vulnerability.
Published: 2026-06-30
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The HP Fan Control App contains a flaw that may allow a local attacker to elevate privileges on the affected machine. The weakness is classified as CWE-428, which involves improper handling or validation of runtime configuration data that can be exploited to gain higher privileges. If successfully triggered, an attacker could execute code with elevated rights, potentially compromising system integrity and confidentiality.

Affected Systems

The vulnerability affects HP Inc.'s HP Fan Control App running on Windows systems. No specific version information is provided, indicating that earlier releases prior to the patched update may be vulnerable. The CPE string confirms the product is Windows‑based.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity for local privilege escalation. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is local: a user with some level of access to the machine can manipulate the application to trigger the escalation. Because no remote component is required, the risk is confined to systems where the app is installed.

Generated by OpenCVE AI on June 30, 2026 at 17:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest HP Fan Control App update released by HP Inc. to remove the flaw.
  • If an update is unavailable, uninstall the HP Fan Control App until an official patch is issued.
  • Disable automatic startup of the HP Fan Control App to reduce the opportunity for exploitation until a patch is applied.

Generated by OpenCVE AI on June 30, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp fan Control App
Vendors & Products Hp
Hp fan Control App

Tue, 30 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mitigate this potential vulnerability.
Title HP Fan Control App – Potential Escalation of Privilege
First Time appeared Hp Inc.
Hp Inc. hp Fan Control App
Weaknesses CWE-428
CPEs cpe:2.3:a:hp_inc.:hp_fan_control_app:*:*:windows:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Fan Control App
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Fan Control App
Hp Inc. Hp Fan Control App
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-06-30T16:45:49.875Z

Reserved: 2026-05-18T19:44:47.365Z

Link: CVE-2026-8864

cve-icon Vulnrichment

Updated: 2026-06-30T16:45:45.963Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:01:09Z

Weaknesses
  • CWE-428

    Unquoted Search Path or Element