Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 8.6 High
EPSS: 1.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

HP has identified multiple externally reported vulnerabilities within the HP Linux Imaging and Printing Software (HPLIP). The affected components could enable an attacker to execute arbitrary code on the target system, elevate privileges, disrupt service availability, disclose sensitive information, or modify files without authorization. The weaknesses are consistent with a heap‑based buffer overflow (CWE‑122) and weak cryptographic key management (CWE‑266).

Affected Systems

The vulnerabilities affect the HP Inc. HP Linux Imaging and Printing Software (HPLIP) for Linux systems. Specific version information was not disclosed in the public advisory, so all current releases of HPLIP that include the affected components are potentially impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity, but the EPSS score of less than 1% shows that exploitation is currently unlikely. HPLIP is not listed in CISA’s KEV catalog, further suggesting a lower exploitation probability. The likely attack vector is remote, possibly via uncovered network interfaces or removable media inputs that interact with HPLIP’s printing services. System administrators should treat this as a serious threat, prioritizing patching when one becomes available.

Generated by OpenCVE AI on September 18, 2026 at 04:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HPLIP to the latest version available from HP’s support resources or use the package manager to apply the vendor‑supplied patch.
  • As a temporary safeguard, disable or restrict network access to the printing services that invoke HPLIP, if possible, until a patch is applied.
  • Monitor system logs for anomalous printer activity or privilege‑escalation attempts, and review firewall rules to block any unauthorized remote access to HPLIP components.

Generated by OpenCVE AI on September 18, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-122
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T11:39:24.037Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91105

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:06.915Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:03.467

Modified: 2026-09-21T17:27:55.557

Link: CVE-2026-91105

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T18:54:53Z

Links: CVE-2026-91105 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:56Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-266

    Incorrect Privilege Assignment