Description
HP
has identified potential security vulnerabilities in the HP Advance software
that may enable elevation of privilege, remote code execution, or arbitrary
file write under certain conditions, impacting the HP Advance server hosting
the software.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in HP Advance software may allow an attacker to gain elevated privileges, execute code remotely, or write arbitrary files on the HP Advance server that hosts the application. The vulnerability is classified with a CVSS score of 8.8, indicating high severity. The EPSS score is below 1 %, meaning the probability of exploitation observed in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote interaction with the HP Advance web interface; the attacker would need to target the server under conditions that enable the flaw to trigger. The consequences for confidentiality, integrity, or availability would be system‑wide if the vulnerability is exploited, as it could allow execution of arbitrary code and modification of critical files on the server.

Affected Systems

HP Inc products HP AC Print & Scan and HP Output Central are impacted when they run the HP Advance software. No specific version numbers are supplied in the data, so any installation of the HP Advance component that is located on a server may be susceptible.

Risk and Exploitability

The high CVSS score of 8.8 reflects serious privilege escalation and remote code execution potential. The EPSS score of less than 1 % indicates that real‑world exploitation is rare but possible. Since the issue is not currently in the KEV catalog, there have been no publicly confirmed exploits, but the presence of a remote code execution pathway means that an attacker who can reach the HP Advance server could potentially compromise the entire system. The lack of an official patch in the available data suggests that users must be proactive in checking for updates from HP and consider compensating controls until a fix is released.

Generated by OpenCVE AI on September 18, 2026 at 02:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and apply the latest HP Advance security patch or firmware update released by HP for this vulnerability.
  • Limit access to the HP Advance server by enabling network segmentation, firewall rules, and strong authentication so that only authorized systems can reach the web interface.
  • Enforce strict file system permissions on the server and monitor for unauthorized file creation or modification to detect attempts at arbitrary file writes.

Generated by OpenCVE AI on September 18, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hp Inc
Hp Inc hp Ac Print & Scan
Hp Inc hp Output Central
Vendors & Products Hp Inc
Hp Inc hp Ac Print & Scan
Hp Inc hp Output Central

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
Title HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Inc Hp Ac Print & Scan Hp Output Central
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T16:06:27.428Z

Reserved: 2026-09-10T19:43:51.079Z

Link: CVE-2026-89084

cve-icon Vulnrichment

Updated: 2026-09-17T16:06:23.127Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:38.833

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-89084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:11:53Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')