Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

HP identified multiple externally reported issues affecting the HPLIP software that could enable remote code execution, privilege escalation, denial‑of‑service, information disclosure, or unauthorized file modification. These vulnerabilities affect several components of HPLIP, yet the CVE does not outline a specific exploitation path. The potential impact includes compromising confidentiality, integrity, or availability for Linux systems that run HPLIP.

Affected Systems

The affected product is HP Linux Imaging and Printing Software (HPLIP) for Linux. No specific version range is listed, so any installation of HPLIP that has not yet been patched by HP is potentially vulnerable. HP Inc. is the sole vendor identified as impacted.

Risk and Exploitability

The CVSS score of 8.4 indicates a high‑severity risk. The EPSS score is below 1 %, suggesting a very low probability of exploitation at the time of the analysis, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is external; an attacker could send crafted payloads or requests to a vulnerable HPLIP component from an untrusted network or local user context. In the absence of a publicly posted exploit and with the low EPSS, the immediate threat is moderate, but the high CVSS warrants remediation.

Generated by OpenCVE AI on September 18, 2026 at 01:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HP‑provided HPLIP update that resolves the identified vulnerabilities
  • If the update is not yet available, temporarily disable or uninstall the HPLIP components until the patch is applied
  • Restrict network exposure of HPLIP services so that only trusted local or network hosts can access them

Generated by OpenCVE AI on September 18, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-494
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-78
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-18T03:55:30.388Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91102

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:59.040Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:03.063

Modified: 2026-09-21T17:28:16.553

Link: CVE-2026-91102

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T18:50:55Z

Links: CVE-2026-91102 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:02Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')