Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch promptly
AI Analysis

Impact

HP identified several vulnerabilities in HPLIP that could allow an attacker to execute code on the system, elevate privileges, crash the service, or read and modify sensitive files. The weaknesses involve integer overflows and insufficient access controls, which are listed as CWE-191 and CWE-266. The potential damage ranges from full system compromise to data disclosure and denial of service.

Affected Systems

The affected product is HP Linux Imaging and Printing Software (HPLIP) from HP Inc. No specific version range is supplied in the CVE record, so all installed instances of HPLIP may be at risk until updated.

Risk and Exploitability

With a CVSS score of 5.1 and an EPSS score below 1%, the likelihood of widespread exploitation is currently low. The vulnerabilities are not yet in CISA’s KEV catalog. Because the issues are externally reported and could be triggered from a networked printer interface, the probable attack vector is remote, although local users or privileged accounts could also exploit the flaws depending on the exact component affected.

Generated by OpenCVE AI on September 17, 2026 at 23:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the most recent HPLIP security update released by HP.
  • Remove or disable any older HPLIP components that might still be present.
  • Limit network access to printer services to trusted hosts only.

Generated by OpenCVE AI on September 17, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

threat_severity

Moderate


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-191
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T13:41:06.632Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91103

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:52.418Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:03.197

Modified: 2026-09-21T17:28:10.193

Link: CVE-2026-91103

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T18:52:28Z

Links: CVE-2026-91103 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)

  • CWE-266

    Incorrect Privilege Assignment