Description
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: 1.0% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Multiple externally reported weaknesses in HP Linux Imaging and Printing Software (HPLIP) could allow a remote attacker to execute arbitrary code, elevate privileges, disrupt service availability, disclose sensitive data, or modify files. The underlying flaw is characterized as a buffer overflow (CWE-122), which can be exploited when the software processes untrusted input. If leveraged, an attacker could compromise the local system and gain full control over the affected machine.

Affected Systems

The vulnerabilities affect HP Linux Imaging and Printing Software (HPLIP) distributed by HP Inc. The data does not specify exact product versions; therefore the potential impact applies to all installations of HPLIP that include the vulnerable components. Users should verify whether their version of HPLIP includes the identified fixes.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity critical flaw, while the EPSS score of less than 1% suggests a low probability of near‑term exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network interactions such as print service requests or related protocols, allowing an attacker to deliver malicious payloads to an unpatched system. The combination of remote exploitation potential and high impact warrants urgent attention.

Generated by OpenCVE AI on September 18, 2026 at 05:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest HPLIP update available from HP support pages to address the identified buffer overflow and related weaknesses.
  • If an immediate patch cannot be applied, disable the HPLIP printing services or uninstall the component to prevent exploitation until a fix is deployed.
  • Limit network access to the printing interfaces by configuring firewall rules to allow only trusted hosts, and monitor log files for anomalous print job activity.

Generated by OpenCVE AI on September 18, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Hp
Hp linux Imaging And Printing
CPEs cpe:2.3:a:hp:linux_imaging_and_printing:*:*:*:*:*:*:*:*
Vendors & Products Hp
Hp linux Imaging And Printing
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Title HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
First Time appeared Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
Weaknesses CWE-122
CPEs cpe:2.3:a:hp_inc.:hp_linux_imaging_and_printing_software_hplip_:*:*:linux:*:*:*:*:*
Vendors & Products Hp Inc.
Hp Inc. hp Linux Imaging And Printing Software Hplip
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hp Linux Imaging And Printing
Hp Inc. Hp Linux Imaging And Printing Software Hplip
cve-icon MITRE

Status: PUBLISHED

Assigner: hp

Published:

Updated: 2026-09-17T11:39:23.731Z

Reserved: 2026-09-14T19:13:23.919Z

Link: CVE-2026-91106

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:02.147Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T19:18:03.587

Modified: 2026-09-21T17:27:05.993

Link: CVE-2026-91106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:54Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow