Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

HP has identified multiple vulnerabilities in the Linux Imaging and Printing Software (HPLIP) that could lead to remote code execution, privilege escalation, denial of service, information disclosure or unauthorized file modification under certain conditions. Each flaw resides in different components of the application and together create a small but real risk for attackers who can trigger the affected code paths. The consequence of exploitation includes potential full control of the affected system, loss of confidentiality, integrity or availability, and the ability to alter or delete system files.

Affected Systems

The only affected product listed is HP Linux Imaging and Printing Software (HPLIP) provided by HP Inc. No specific version numbers are attached to the report, meaning all released releases of the software may need to be considered at risk until HP confirms supported fixes.

Risk and Exploitability

The CVSS score of 5.1 reflects the moderate severity of the overall vulnerability bundle, and the EPSS score of less than 1 % indicates a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited widespread exploitation. The likely attack vector is remote, inferred from the description of "remote code execution" and "external reporting". An attacker would need to manipulate or coerce HPLIP, presumably via a network-exposed service or an operating system component that invokes HPLIP functions, to trigger the flaws.

Generated by OpenCVE AI on September 17, 2026 at 23:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest HPLIP update available from HP’s support site, ensuring all known patches are applied.
  • Reboot the system after updating to restart all HPLIP services and apply the new configurations.
  • If an update is not immediately available, restrict HPLIP exposure by disabling unnecessary services or blocking related network traffic until a patch is released.

Generated by OpenCVE AI on September 17, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-129
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T13:41:06.932Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91101

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:56.959Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:02.947

Modified: 2026-09-21T17:28:23.030

Link: CVE-2026-91101

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T18:49:00Z

Links: CVE-2026-91101 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:07Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-266

    Incorrect Privilege Assignment