Junglewise Threat Intelligence

CVE-2026-91102: HP HPLIP multiple vulnerabilities enabling remote code execution

CVE-2026-91102 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Executive brief

HP HPLIP (HP Linux Imaging and Printing) is a software suite that manages HP printers and multifunction devices on Linux systems. Multiple vulnerabilities in HPLIP could allow attackers to execute arbitrary code remotely, escalate privileges, crash the service, steal data, or modify files without authorization, potentially compromising systems that manage printer infrastructure and related network services.

Technical details

HPLIP contains multiple unspecified vulnerabilities affecting several software components. The vulnerabilities enable a range of attack outcomes including remote code execution, privilege escalation, denial of service, information disclosure, and unauthorized file modification. An attacker with network access to HPLIP services could exploit these flaws under certain conditions. HP has released patches to remediate the identified issues; affected users should apply the remediation provided in support document ish_15646959-15646984-16.

Affected products

  • HP HPLIP

Timeline

  • 2026-09-16: disclosed

References

Related threats