CVE-2026-91098 PUBLISHED

HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities

Assigner: hp
Reserved: 14.09.2026 Published: 16.09.2026 Updated: 17.09.2026

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor HP Inc.
Product HP Linux Imaging and Printing Software (HPLIP)
Versions Default: affected
  • affected from 0 to 3.26.6 (excl.)

Credits

  • Trung Nguyen (@everping) of CyStack finder
  • Nir Yehoshua, Cipher Security Labs finder

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE