Junglewise Threat Intelligence

CVE-2026-91104: HP HPLIP multiple remote code execution and privilege escalation vulnerabilities

CVE-2026-91104 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Executive brief

HP's HPLIP (HP Linux Imaging and Printing) is a widely used printing and scanning software suite. Multiple vulnerabilities in HPLIP could allow attackers to execute arbitrary code, escalate privileges, disrupt service, or modify files on affected systems without authorization. These flaws could compromise printer and imaging security across organizations relying on HP hardware and software integration.

Technical details

CVE-2026-91104 encompasses multiple vulnerabilities in HP's Linux Imaging and Printing (HPLIP) software, a system library for printer and scanner support. The advisory reports that affected components can enable remote code execution, privilege escalation, denial of service, information disclosure, and unauthorized file modification. The network attack vector and critical CVSS score (9.8) suggest at least one flaw is remotely exploitable with no authentication or user interaction required. HP has released remediated versions; users should update HPLIP to the patched release immediately.

Affected products

  • HP HPLIP <UNKNOWN>

Timeline

  • 2026-09-16: disclosed

References

Related threats