Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

HP has identified multiple vulnerabilities in the HP Linux Imaging and Printing Software (HPLIP) that could enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The exact mechanisms are not detailed, but the potential to execute arbitrary code or modify files on the host is indicated.

Affected Systems

The affected vendor is HP Inc., with the product HP Linux Imaging and Printing Software (HPLIP). Specific affected versions are not listed in the available data, so organizations should ensure they are running the latest patched release of HPLIP.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low exploitation probability. The vulnerability is not listed in CISA KEV, reducing the likelihood of widespread exploitation. The attack vector is inferred to be remote, possibly involving malicious print jobs or network traffic, but the precise conditions remain unspecified.

Generated by OpenCVE AI on September 17, 2026 at 23:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPLIP patch or upgrade to the newest release to eliminate the known vulnerabilities.
  • If a patch is unavailable, remove or disable the affected HPLIP components to prevent exploitation.
  • Limit the privileges of the HPLIP service to the minimum required to perform printing tasks, reducing the impact of any potential compromise.

Generated by OpenCVE AI on September 17, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-61
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T13:41:06.477Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91099

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:50.132Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:02.490

Modified: 2026-09-21T17:28:39.180

Link: CVE-2026-91099

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T18:45:51Z

Links: CVE-2026-91099 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:16Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-61

    UNIX Symbolic Link (Symlink) Following