CVE-2026-91098
published 2026-09-16CVE-2026-91098: HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.00%
61.5th percentile
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hplip | — | — |
| hp | linux_imaging_and_printing | < 3.26.6 | 3.26.6 |
| hp_inc | hp_linux_imaging_and_printing_software | < 3.26.6 | 3.26.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
vendor_redhat·2026-09-16·CVSS 8.6
CVE-2026-91098 [HIGH] CWE-494 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
A flaw was found in HP Linux Imaging and Printing (HPLIP) software. Multiple vulnerabilities exist that could allow a remote attacker to achieve remote code execution, escalate privileges, cause a denial of service, disclose information, or modify files without authorization under certain conditions.
Mitigation: Mitigation for this issue is either not available or the currently availa
VulDB
HP HPLIP up to 3.26.5 privilege escalation (Nessus ID 346883)
vuldb·2026-09-18·CVSS 8.6
CVE-2026-91098 [HIGH] HP HPLIP up to 3.26.5 privilege escalation (Nessus ID 346883)
A vulnerability described as critical has been identified in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation results in privilege escalation.
This vulnerability was named CVE-2026-91098. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP.
ghsa_unreviewed·2026-09-16
CVE-2026-91098 [HIGH] CWE-122 HP has identified and remediated multiple externally reported vulnerabilities within HPLIP.
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-91098 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation [fedora-all]
bugzilla·2026-09-17·CVSS 8.6
CVE-2026-91098 [HIGH] CVE-2026-91098 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation [fedora-all]
CVE-2026-91098 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Bugzilla
CVE-2026-91098 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
bugzilla·2026-09-16·CVSS 8.6
CVE-2026-91098 [HIGH] CVE-2026-91098 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
CVE-2026-91098 hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
2026-09-16
Published