CVE-2026-82346
massLocal Privilege Escalation in HP ImageDiags before 5.0.0.36
HP ImageDiags, a diagnostics utility distributed by HP for its Windows-based commercial PCs, is affected by a local privilege escalation vulnerability in versions prior to 5.0.0.36. HP attributes the flaw to insufficient access controls, and the CWE-379 mapping points to creation of temporary files with insecure permissions as the likely mechanism. The CVSS 4.0 vector confirms a local attack requiring only low privileges (with active user interaction), and successful exploitation yields high impact on the confidentiality, integrity, and availability of the affected machine — effectively granting the attacker elevated control of that system. Only HP endpoints with ImageDiags installed, typically enterprise-managed commercial PCs, are affected. There is no known exploitation: the issue is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.
What to do: Inventory Windows endpoints for HP ImageDiags and update to version 5.0.0.36 or later per HP's security advisory. Until patched, limit use of the tool on shared or multi-user workstations and treat unprivileged local code execution on those hosts as elevated risk. No exploitation is currently known, so remediation through normal patch cycles is reasonable.
| HP ImageDiags | All versions prior to 5.0.0.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
- Weakness
- CWE-379
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.