ZeroHour

CVE-2026-91102

mass

OS Command Injection Flaws in HP Linux Imaging and Printing (HPLIP)

CVSS 4.0
8.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-91102 covers multiple externally reported vulnerabilities in HP's HPLIP (HP Linux Imaging and Printing) software, including an OS command injection issue (CWE-78), with an overall CVSS 4.0 score of 8.4 (high). The flaws can enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The CVSS vector indicates a local attack vector requiring no privileges but user interaction, suggesting an attacker must get a local user to trigger an affected HPLIP component with attacker-controlled input (e.g., via a crafted print or scan job). Anyone running HPLIP to drive HP printers or scanners on Linux is affected, and HPLIP is widely bundled with major distributions. HP has already remediated the issues; there is no evidence of exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.

What to do: Update HPLIP to the patched release referenced in HP's security advisory (the fixed version number is not named in the available data), or take the updated hplip package from your distribution as soon as it is offered. On systems without HP printers or scanners (e.g., servers), remove the hplip package entirely to shrink the attack surface. Check HP's advisory for the specific affected components and fixed versions, as this CVE bundles several distinct flaws.

Affected
HPLIP (HP Linux Imaging and Printing)
Estimated exposure
massplausibly millions of Linux installations that bundle or install HPLIP — HPLIP is the standard driver stack for HP printing/scanning and ships in the default package repositories of all major Linux distributions (Ubuntu, Debian, Fedora, openSUSE, Arch), giving an install base on the order of millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Weakness
CWE-78
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.