Remote Code Execution and Privilege Escalation in HP's HPLIP Software
CVE-2026-91097

7HIGH

Key Information:

Vendor

HP

Vendor
CVE Published:
16 September 2026

What is CVE-2026-91097?

HP's HPLIP software has been found to contain several vulnerabilities that could allow an attacker to execute arbitrary code remotely, escalate privileges, cause denial of service, disclose sensitive information, or modify files without authorization. These vulnerabilities stem from issues in different components of the software and could be exploited under specific conditions, leading to significant security risks.

Affected Version(s)

HP Linux Imaging and Printing Software (HPLIP) Linux 0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trung Nguyen (@everping) of CyStack
Nir Yehoshua, Cipher Security Labs
.