Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

HP identified several critical weaknesses in its Linux Imaging and Printing Software (HPLIP). The documented issues revolve around a buffer overflow flaw (CWE-122) that can be triggered by crafted input to the printer service. When exploited, an attacker can gain code execution on the host, elevate privileges, crash the service, steal sensitive data, or modify files the printer process is allowed to write. The damage potential extends from isolated service disruption to full system compromise, depending on the extent of the privilege escalation achieved.

Affected Systems

The vulnerabilities affect HP’s HPLIP package for Linux, which is commonly installed on workstation and server systems that use HP printers. No specific version numbers are listed in the advisory, so all installations of HPLIP on Linux should be considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. The EPSS value of less than 1% shows that, although the vulnerability exists, the current exploitation probability is low, likely because it requires the attacker to have network or local access to the printer spool service. The flaw is not yet listed in the CISA Known Exploited Vulnerabilities catalog. An attacker who can reach a vulnerable printer service from the network, or who has local privileges, could send malicious payloads that trigger the buffer overflow and obtain code execution. The high impact combined with the low exploitation probability recommends prompt remediation.

Generated by OpenCVE AI on September 18, 2026 at 04:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update HPLIP to the latest version released by HP, which contains the buffer‑overflow fix.
  • If the updated package is unavailable, uninstall or disable any unused printer drivers and modules that invoke HPLIP.
  • Configure firewall or host access controls to restrict network connections to the printer spooling service to trusted hosts only.
  • Monitor printer service logs for anomalous activity and consider revoking printed configuration changes that are not expected.

Generated by OpenCVE AI on September 18, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-122
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T11:39:24.197Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91104

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:03.320

Modified: 2026-09-21T17:28:02.620

Link: CVE-2026-91104

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:59Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow