Executive brief
HP HPLIP is a printing and imaging software suite used to manage printers and scanners across Windows, macOS, and Linux systems. Multiple vulnerabilities have been discovered that could allow attackers to execute arbitrary code, escalate privileges, or modify files on affected systems, potentially compromising printer and host security.
Technical details
HP HPLIP contains multiple vulnerabilities affecting several software components, including potential remote code execution, privilege escalation, denial of service, information disclosure, and unauthorized file modification flaws. The vulnerabilities are externally reported and have been remediated by HP. Attack vectors and specific preconditions vary by flaw; however, given the CVSS score of 9.8, at least one vulnerability is likely network-accessible with minimal or no authentication required. Patches are available through HP's support documentation.
Affected products
- HP HPLIP
Timeline
- 2026-09-16: disclosed