Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 7 High
EPSS: 1.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

HP identified multiple externally reported vulnerabilities in the HPLIP package. The flaws affect several components and could allow an attacker to execute arbitrary code on a faulty system, elevate privileges, crash the application, steal confidential information, or modify files without authorization. The weaknesses include a classic off‑by‑one or buffer overrun (CWE‑787) and a code‑execution or command injection (CWE‑94).

Affected Systems

The affected product is HP Linux Imaging and Printing Software (HPLIP) distributed by HP Inc. The specific version numbers that contain the flaw were not disclosed in the advisory, but any installation of HPLIP prior to the vendor’s latest release should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7 reflects a high‑severity risk. The EPSS score of less than 1 % indicates a low probability that the vulnerability will be actively exploited at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the likely attack vector is remote, as the flaw involves components that interface over the network or accept external input. If abused, an attacker could gain a local or remote foothold, persist on the host, or disrupt printing services for users.

Generated by OpenCVE AI on September 17, 2026 at 23:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HP Linux Imaging and Printing Software to the latest version that includes the security fix, available from HP’s support site or Linux package repositories.
  • Disable or uninstall any unused HPLIP services and utilities from the system.
  • Limit file system permissions on HPLIP directories and executables to the minimum necessary, and configure the firewall to block external access to printing‑related ports unless required.
  • Monitor system logs for unexpected printing activity.

Generated by OpenCVE AI on September 17, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-787
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T13:41:06.327Z

Reserved: 2026-09-14T19:13:23.918Z

Link: CVE-2026-91097

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:48.010Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:02.070

Modified: 2026-09-21T17:28:56.030

Link: CVE-2026-91097

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T18:39:12Z

Links: CVE-2026-91097 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:24Z

Weaknesses
  • CWE-787

    Out-of-bounds Write

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')