Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerabilities reside in several components of the HPLIP software stack and are capable of triggering a range of serious effects. They can allow an attacker to execute arbitrary code, elevate privileges, cause denial of service, disclose information, or modify files that should be protected. The presence of a buffer overflow weakness (CWE‑122) and an unauthorized file modification vulnerability (CWE‑494) implies that unsafe handling of external input or insufficient access checks are the root causes.

Affected Systems

HP Inc. HP Linux Imaging and Printing Software, which runs on Linux platforms. The CVE does not list specific release numbers, indicating that multiple components across the distribution are affected.

Risk and Exploitability

The CVSS score of 8.6 classifies the problem as high severity, while an EPSS of less than 1 % suggests that a widespread exploitation is currently unlikely. The issue is not listed in CISA’s KEV catalog. Attackers would most likely need to interact with HPLIP services or provide malicious input through a remote interface, exploiting the identified weaknesses to achieve code execution or privilege escalation.

Generated by OpenCVE AI on September 18, 2026 at 04:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest available HPLIP patch from HP’s support site to address the identified security issues.
  • If HPLIP is not required for your environment, uninstall or disable the program to eliminate the attack surface.
  • If removal is not feasible, limit network exposure by configuring firewall rules or host-based access controls to restrict communication with HPLIP services to trusted hosts only.

Generated by OpenCVE AI on September 18, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-494
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-122
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T11:39:24.349Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91098

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:11.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:02.247

Modified: 2026-09-21T17:28:47.950

Link: CVE-2026-91098

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T18:43:03Z

Links: CVE-2026-91098 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:20Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-494

    Download of Code Without Integrity Check