CVE-2026-89082
moderateCritical unauthenticated code injection in HP Advance server enables RCE and file writes
HP has disclosed code injection flaws (CWE-94) in HP Advance server software that, under certain conditions, can lead to elevation of privilege, remote code execution, or arbitrary file write on the server hosting HP Advance. The CVSS 4.0 vector (AV:N/AC:L/PR:N/UI:N) indicates the issues are reachable over the network without authentication or user interaction, with high impact to the confidentiality, integrity, and availability of the server. A successful attacker could gain code execution or write arbitrary files on the HP Advance server, which typically anchors an organization's mobile and managed printing workflows. Any organization operating an HP Advance server is potentially affected. As of this analysis the flaws are not listed in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Consult HP's security bulletin for CVE-2026-89082 and upgrade HP Advance server to the fixed release HP recommends, since the advisory data here does not state version numbers. In the meantime, limit network exposure of the HP Advance server to trusted internal segments or VPN access, as the flaws are exploitable remotely without authentication. Verify whether your Advance server is internet-reachable and monitor HP release notes for patched builds.
| HP Inc. HP Advance (server component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.