securityonline.info 17 Sept 2026, 15:01 UTC

HP Fixes Five Critical HPLIP Flaws Enabling Code Execution

HP Fixes Five Critical HPLIP Flaws Enabling Code Execution

HP has released HPLIP version 3.26.6 to address five reported vulnerabilities in its Linux printing software. The affected issues are CVE-2026-91106 and CVE-2026-91104, each rated 9.3 under CVSSv4; CVE-2026-91105 and CVE-2026-91098, both rated 8.6; and CVE-2026-91102, rated 8.4. All versions before 3.26.6 across supported Linux distributions are affected.

The article says the flaws could allow arbitrary code execution, privilege escalation, denial of service, information disclosure or unauthorised file modification, depending on the vulnerability and conditions.

According to the report, the weaknesses affect driver and parsing components. Crafted print requests could potentially trigger memory corruption without authentication, while local attackers could exploit buffer flaws to write files to restricted locations. However, HP has reportedly confirmed that there is no known active exploitation in the wild and no public proof-of-concept code for these issues.

Administrators are advised to update HPLIP to version 3.26.6 or later using their distribution’s package manager or HP’s installation packages, and to consult HP’s security advisory for further details.

View full article

Article by CyberSIXT