Junglewise Threat Intelligence

CVE-2026-8631: HP HPLIP privilege escalation via integer overflow in hpcups

CVE-2026-8631 · Severity: info · CVSS 9.3 · Published 2026-05-20

Vendors: Hp.

Executive brief

A security vulnerability exists in HP's Linux printing software, which is used to manage printing and imaging on Linux-based systems. An attacker could exploit this flaw to gain administrative control over the system or run unauthorized programs. This could lead to a complete compromise of the affected computer and any sensitive data stored on it.

Technical details

An integer overflow vulnerability exists in the hpcups processing path of the HP Linux Imaging and Printing (HPLIP) software. The flaw is triggered when the software handles specially crafted print data, leading to a heap-based buffer overflow (CWE-122). A remote, unauthenticated attacker can exploit this by sending malicious print jobs to a system running HPLIP. Successful exploitation can result in arbitrary code execution with the privileges of the printing process or full local privilege escalation. HP has acknowledged the issue in security bulletin HPSBPI04118.

Affected products

  • HP Linux Imaging and Printing Software (HPLIP)

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory

References

Related threats