Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The weaknesses are tied to improper privilege management (CWE-266) and operating‑system command injection (CWE-78).

Affected Systems

The affected product is HP Linux Imaging and Printing Software (HPLIP) for Linux. No specific version ranges are listed, so any installation of HPLIP may be impacted until the vendor releases a fixed build.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity, while an EPSS score of less than 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, further indicating that documented exploitation is not widespread as of this assessment. The likely attack vector is remote, as the issues allow code execution from outside the local system, implying that network‑exposed HPLIP services could be targeted. This risk is mitigated by applying vendor fixes and securing service exposure.

Generated by OpenCVE AI on September 17, 2026 at 23:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update HPLIP to the latest release available from HP, which includes the remediation for the identified vulnerabilities.
  • If an immediate update cannot be applied, isolate or disable the HPLIP service from external network access until the fix is installed.
  • Configure the print environment to run with the least privileges necessary, ensuring that only trusted users can invoke print drivers or modify configuration files, thereby reducing the impact of potential privilege‑escalation or command‑injection paths.

Generated by OpenCVE AI on September 17, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L'}

threat_severity

Moderate


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-78
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T13:41:06.784Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91100

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:54.668Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:02.820

Modified: 2026-09-21T17:28:29.430

Link: CVE-2026-91100

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T18:47:42Z

Links: CVE-2026-91100 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')