Junglewise Threat Intelligence

CVE-2026-91100: HP HPLIP remote code execution and privilege escalation

CVE-2026-91100 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Executive brief

HP HPLIP is a software package used to manage printer and multifunction device operations on computer systems. Multiple vulnerabilities in HPLIP components could allow attackers to execute arbitrary code, escalate privileges, disrupt service availability, or access sensitive information under certain conditions.

Technical details

HP has identified and remediated multiple externally reported vulnerabilities across several HPLIP software components. The vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, and unauthorized file modification under certain conditions. Attack vectors and specific technical details are not fully specified in the available advisory; however, the combination of RCE and privilege escalation capabilities suggests network-accessible components with insufficient input validation or authorization controls. HP has published patches to address these issues.

Affected products

  • HP HPLIP

Timeline

  • 2026-09-16: disclosed

References

Related threats