Description
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Patch urgently
AI Analysis

Impact

HP Advance software contains a code injection flaw that can lead to a wide range of security breaches, including elevation of privilege, remote code execution, and arbitrary file write on the HP Advance server. The weakness is a classic code execution vulnerability. An attacker who can influence the problematic input would be able to run arbitrary commands, gain administrative rights, and modify or create files on the server, potentially compromising sensitive data or the integrity of the entire printing and scanning infrastructure.

Affected Systems

The affected systems are the HP Advance server that hosts the HP AC Print & Scan and HP Output Central applications. No specific affected firmware or software versions are listed, so all installations of HP Advance are presumed at risk until a vendor‑issued fix is applied.

Risk and Exploitability

The base CVSS score of 9.3 indicates a high‑severity threat. The EPSS score is reported as less than 1%, which suggests that exploitation in the wild has not yet been widely observed, although the low probability does not eliminate risk. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, requiring the ability to deliver crafted input to the HP Advance server, for example through exposed network services or web interfaces. Once exploited, the attacker obtains core system capabilities.

Generated by OpenCVE AI on September 18, 2026 at 02:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy the latest vendor‑supplied patch for HP Advance, ensuring the code injection flaw is fixed.
  • If a patch is not immediately available, restrict external network access to the HP Advance server or isolate it behind a firewall to limit the reach of potential attackers.
  • As a temporary workaround, remove or disable any remote management or scripting features used by HP AC Print & Scan and HP Output Central until a permanent fix is applied.

Generated by OpenCVE AI on September 18, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hp Inc
Hp Inc hp Ac Print & Scan
Hp Inc hp Output Central
Vendors & Products Hp Inc
Hp Inc hp Ac Print & Scan
Hp Inc hp Output Central

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
Title HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Inc Hp Ac Print & Scan Hp Output Central
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T16:08:03.733Z

Reserved: 2026-09-10T19:43:49.343Z

Link: CVE-2026-89082

cve-icon Vulnrichment

Updated: 2026-09-17T16:07:56.591Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:38.573

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-89082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')