ZeroHour

CVE-2026-89084

moderate

Path Traversal in HP Advance Server Enables Arbitrary File Write, RCE

CVSS 4.0
8.8 high
EPSS
Published
()
Modified
AI analysis

HP Advance, HP's enterprise secure print-management software, contains path traversal flaws (CWE-22) that can permit an arbitrary file write on the server hosting the software under certain conditions. The CVSS 4.0 vector indicates the issues are reachable over the network by an unauthenticated attacker with no user interaction required. By writing files to attacker-controlled locations, an attacker can achieve elevation of privilege or remote code execution on the HP Advance server, with high impact to integrity and availability. Any organization running an on-premises HP Advance server, typically deployed to support managed or secure printing, is potentially affected. There is currently no evidence of exploitation in the wild, no known public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.

What to do: Upgrade HP Advance to the fixed release identified in HP's security bulletin for CVE-2026-89084, as no workaround is documented in the available data. Until patched, restrict network access to the HP Advance server to trusted management and print networks and check the host filesystem for unexpectedly written or modified files. Because the attack vector is network-based and unauthenticated, prioritize patching any deployment that is internet-facing or broadly reachable.

Affected
HP Advance (software and the HP Advance server hosting it)
Estimated exposure
moderatelikely on the order of thousands of enterprise print-management servers (estimate; no public install counts available) — HP Advance is an enterprise secure/managed-print server product generally deployed as a single server per organization under HP print-management offerings, implying an installed base in the thousands rather than consumer scale, but no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

Weakness
CWE-22
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.