Executive brief
HP Easy Start is a macOS application used to install HP printer software and drivers. CVE-2026-12556 allows software updates to be downloaded over cleartext (unencrypted) connections due to relaxed App Transport Security (ATS) settings and FTP fallback, enabling a network attacker on the same LAN segment or with DNS control to intercept and modify installation packages, potentially leading to unauthorized code execution with administrative privileges.
Technical details
CVE-2026-12556 is a cleartext transport vulnerability (CWE-319) in HP Easy Start's software-delivery mechanism. The application fails to enforce encrypted downloads due to relaxed ATS policy and permits FTP as a fallback, allowing an attacker positioned on the network or with DNS control to perform a man-in-the-middle attack. The vulnerability requires an unprivileged local user on a shared LAN segment and timing/prediction (AT:P), but the attack chain combines with the privileged installation workflow to achieve full system compromise. The vulnerability affects versions prior to 2.16.7.260722 and has been remediated in that release. CVSS 4.0 score is 7.7 (High) with vector AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H.
Affected products
- HP Inc. Easy Start for macOS prior to 2.16.7.260722
Timeline
- 2026-09: disclosed: Cipher Security Labs published research covering CVE-2026-12556 and related vulnerabilities
- 2026-07-29: patched: Remediation validated in HP Easy Start 2.16.7 (build 260722)
- 2026-08-24: other: CVE-2026-12556 published on NVD