CVE-2026-89084
moderatePath Traversal in HP Advance Server Enables Arbitrary File Write, RCE
HP Advance, HP's enterprise secure print-management software, contains path traversal flaws (CWE-22) that can permit an arbitrary file write on the server hosting the software under certain conditions. The CVSS 4.0 vector indicates the issues are reachable over the network by an unauthenticated attacker with no user interaction required. By writing files to attacker-controlled locations, an attacker can achieve elevation of privilege or remote code execution on the HP Advance server, with high impact to integrity and availability. Any organization running an on-premises HP Advance server, typically deployed to support managed or secure printing, is potentially affected. There is currently no evidence of exploitation in the wild, no known public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.
What to do: Upgrade HP Advance to the fixed release identified in HP's security bulletin for CVE-2026-89084, as no workaround is documented in the available data. Until patched, restrict network access to the HP Advance server to trusted management and print networks and check the host filesystem for unexpectedly written or modified files. Because the attack vector is network-based and unauthenticated, prioritize patching any deployment that is internet-facing or broadly reachable.
| HP Advance (software and the HP Advance server hosting it) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.