Executive brief
HP HPLIP is software that manages printer and scanner functionality on Linux systems. Multiple vulnerabilities in HPLIP could allow attackers to execute arbitrary code, escalate privileges, disrupt service availability, access sensitive information, or modify files on affected systems, depending on the specific flaw and system configuration.
Technical details
HP has patched multiple vulnerabilities affecting various components within HPLIP (HP Linux Imaging and Printing). The vulnerabilities span several classes including remote code execution, privilege escalation, denial of service, and information disclosure. Attack vectors and specific preconditions are not detailed in the available advisory text, but the CVSS 9.8 score and remote code execution capability suggest network-reachable attack surface with minimal authentication or user interaction required. Patches have been released; users should update to the latest HPLIP version.
Affected products
- HP HPLIP
Timeline
- 2026-09-16: disclosed