CVE-2026-89084 PUBLISHED

HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write

Assigner: hp
Reserved: 10.09.2026 Published: 16.09.2026 Updated: 16.09.2026

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor HP Inc
Product HP AC Print & Scan
Versions Default: unaffected
  • affected from 0 to <V1R4.0.027 (excl.)
Vendor HP Inc
Product HP Output Central
Versions Default: unaffected
  • affected from 0 to <V1R4.0.029 (excl.)

Credits

  • Joseph Chiarchiaro, Independent Security Researcher finder

References

Problem Types

  • CWE-22 CWE