ZeroHour

CVE-2026-89083

Unauthenticated code-injection RCE and arbitrary file write in HP Advance server

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

HP has disclosed code-injection flaws (CWE-94) in HP Advance server software that, under certain conditions, can lead to elevation of privilege, remote code execution, or arbitrary file writes on the server hosting the product. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates the flaws are triggerable remotely over a network with low attack complexity, no privileges required, and no user interaction. A successful attacker could gain highly confidential read access on the server and achieve high confidentiality and integrity impact on subsequent (connected) systems, enabling privilege escalation, code execution, or malicious file placement. Any organization running HP Advance, an enterprise print/output-management platform typically hosted on an on-premises server, is affected. No public proof-of-concept is known and the issue is not listed in CISA's KEV, so exploitation has not been confirmed.

What to do: Upgrade HP Advance to the fixed release identified in the HP security bulletin, since the advisory data available here does not specify affected or fixed version numbers. Restrict network access to the Advance server (internal or VPN only, not directly internet-exposed) and check server logs for unauthenticated requests or unexpected file writes. Given the high confidentiality and subsequent-system impact ratings, also review accounts and adjacent systems reachable from the Advance host after patching.

Affected
HP Advance (server hosting the software, on-premises deployment)
Estimated exposure
unknown (no public install-base or internet-exposure data for HP Advance server deployments) — HP Advance is an enterprise print/output-management product typically deployed on internal corporate servers rather than internet-facing hosts, and no public active-install counts or exposed-device scan data exist to ground a magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

Weakness
CWE-94
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.