Executive brief
HP's HPLIP (HP Linux Imaging and Printing) is a widely used printing and scanning software suite. Multiple vulnerabilities in HPLIP could allow attackers to execute arbitrary code, escalate privileges, disrupt service, or modify files on affected systems without authorization. These flaws could compromise printer and imaging security across organizations relying on HP hardware and software integration.
Technical details
CVE-2026-91104 encompasses multiple vulnerabilities in HP's Linux Imaging and Printing (HPLIP) software, a system library for printer and scanner support. The advisory reports that affected components can enable remote code execution, privilege escalation, denial of service, information disclosure, and unauthorized file modification. The network attack vector and critical CVSS score (9.8) suggest at least one flaw is remotely exploitable with no authentication or user interaction required. HP has released remediated versions; users should update HPLIP to the patched release immediately.
Affected products
- HP HPLIP <UNKNOWN>
Timeline
- 2026-09-16: disclosed