Remote Code Execution and Information Disclosure in HPLIP by HP
CVE-2026-91101

5.1MEDIUM

Key Information:

Vendor

HP

Vendor
CVE Published:
16 September 2026

What is CVE-2026-91101?

HP has proactively addressed several reported vulnerabilities within its HPLIP software. These vulnerabilities, found in multiple components of HPLIP, could allow an attacker to execute remote code, escalate privileges, deny service, disclose sensitive information, or modify files without authorization if exploited under specific circumstances. It is crucial for users to apply the latest updates to mitigate these risks effectively.

Affected Version(s)

HP Linux Imaging and Printing Software (HPLIP) Linux 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nir Yehoshua, Cipher Security Labs
.