Executive brief
A security vulnerability has been found in HP's Linux printing and imaging software, which is used to manage HP printers and scanners on Linux systems. An attacker with basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, installation of malicious software, or complete disruption of the affected machine.
Technical details
A command injection vulnerability (CWE-77) exists in the HP Linux Imaging and Printing Software (HPLIP). The flaw stems from improper neutralization of special elements used in an operating system command. A local attacker with low privileges can exploit this vulnerability to execute arbitrary commands with elevated permissions. Successful exploitation allows for full system compromise (High Confidentiality, Integrity, and Availability impact). The vulnerability is tracked as CVE-2026-8632 and has been assigned a CVSS 4.0 base score of 8.5 by the vendor.
Affected products
- HP Linux Imaging and Printing Software (HPLIP)
Timeline
- 2026-05-20: disclosed: Initial disclosure by HP and NVD publication.