Junglewise Threat Intelligence

CVE-2026-91105: HP HPLIP multiple vulnerabilities leading to remote code execution

CVE-2026-91105 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Executive brief

HP HPLIP is a printing and imaging system used across HP's printers, scanners, and multifunction devices. Multiple vulnerabilities in HPLIP software components could allow attackers to remotely execute code, escalate privileges, cause service outages, disclose sensitive information, or modify files without authorization on affected systems.

Technical details

HP has patched multiple vulnerabilities in HPLIP affecting several software components. These vulnerabilities span multiple attack classes including remote code execution, privilege escalation, denial of service, information disclosure, and unauthorized file modification. The vulnerabilities are remotely exploitable under certain conditions, though specific attack vectors and preconditions (such as authentication requirements or user interaction) are not detailed in the available advisory summary. Affected organizations should apply HP's published security patches immediately.

Affected products

  • HP HPLIP

Timeline

  • 2026-09-16: disclosed

References

Related threats