HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)
HP Advance and Output Central have unauthenticated SYSTEM RCE, an auth bypass, and arbitrary file write flaws.
A Full Disclosure post reports three vulnerabilities in HP Advance and HP Output Central, with HP AC Print & Scan also named in HP's update table. CVE-2026-89082, CVE-2026-89083, and CVE-2026-89084 cover unauthenticated remote code execution as SYSTEM, an authorization bypass, and arbitrary file write or delete. The excerpt does not say the flaws are being exploited.
- Unauthenticated remote code execution as SYSTEM
- Authorization bypass plus arbitrary file write and delete
- CVE-2026-89082, CVE-2026-89083, and CVE-2026-89084
- Affects HP Advance, Output Central, and AC Print & Scan
Vulnerabilities mentionedAll →
- CVE-2026-890829.3—Critical unauthenticated code injection in HP Advance server enables RCE and file writespublished · HP Inc. HP Advance (server component)
- CVE-2026-890839.3—Unauthenticated code-injection RCE and arbitrary file write in HP Advance serverpublished · HP Advance (server hosting the software, on-premises deployment)+1 related
Posted by Joe via Fulldisclosure on Sep 22 HP Advance / HP Output Central Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file write/delete CVE-2026-89082, CVE-2026-89083, CVE-2026-89084 ================================================================ SUMMARY ================================================================ Vendor: HP Inc. Product family named by HP: HP Advance Products in HP's update table: HP AC Print & Scan; HP Output Central Components:...
This source does not provide full text. Read it at seclists.org.