CVE-2026-89083
Unauthenticated code-injection RCE and arbitrary file write in HP Advance server
HP has disclosed code-injection flaws (CWE-94) in HP Advance server software that, under certain conditions, can lead to elevation of privilege, remote code execution, or arbitrary file writes on the server hosting the product. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates the flaws are triggerable remotely over a network with low attack complexity, no privileges required, and no user interaction. A successful attacker could gain highly confidential read access on the server and achieve high confidentiality and integrity impact on subsequent (connected) systems, enabling privilege escalation, code execution, or malicious file placement. Any organization running HP Advance, an enterprise print/output-management platform typically hosted on an on-premises server, is affected. No public proof-of-concept is known and the issue is not listed in CISA's KEV, so exploitation has not been confirmed.
What to do: Upgrade HP Advance to the fixed release identified in the HP security bulletin, since the advisory data available here does not specify affected or fixed version numbers. Restrict network access to the Advance server (internal or VPN only, not directly internet-exposed) and check server logs for unauthenticated requests or unexpected file writes. Given the high confidentiality and subsequent-system impact ratings, also review accounts and adjacent systems reachable from the Advance host after patching.
| HP Advance (server hosting the software, on-premises deployment) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.