External risk intelligence

HP HPLIP Multiple Vulnerabilities

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-91104

HPLIP (HP Linux Imaging and Printing) is software designed to support printer and scanner functionality on local Linux systems. It is primarily used on individual workstations or local print servers and is not designed to be exposed to the public internet.

Remote Code Execution

Hp Linux Imaging And Printing

before 3.26.6

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

HP has addressed vulnerabilities in its Linux Imaging and Printing software that could have allowed remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification.

  • Software flaw allows remote control or data tampering.
  • HP printer/scanner software may be affected.
  • Confirm relevance and any potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit vulnerabilities in HPLIP software by sending specially crafted data over the network. This could allow them to execute arbitrary code, elevate their privileges, disrupt services, expose sensitive information, or modify files without authorization.

  • No authentication or network exposure required.
  • Vulnerable software components are triggered.
  • Risk of remote code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in HP's Linux Imaging and Printing software could potentially allow an attacker to execute code remotely, escalate privileges, cause a denial of service, disclose information, or modify files without authorization when supported by the advisory.

  • System data and configuration files could be affected.
  • Exposure could happen through network access.
  • Unauthorized actions could disrupt service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This advisory impacts HP's Linux Imaging and Printing (HPLIP) software. Given the potential for remote code execution and privilege escalation, Platform Teams or Linux System Administrators responsible for managing print and imaging infrastructure should take the lead. The first practical step involves identifying all Linux systems where HPLIP is installed, assessing their internet reachability and business criticality, and then coordinating remediation efforts with the appropriate system owners.

  • Identify HPLIP installation locations.
  • Verify system reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is HP Linux Imaging and Printing (HPLIP)?

HPLIP is a collection of open-source drivers and tools provided by HP. It enables Linux users to connect, manage, and utilize HP printers and scanners for tasks like printing, scanning, and device maintenance on workstations or local print servers.

What does CVE-2026-91104 mean by CWE-122?

CWE-122 refers to a heap-based buffer overflow. In plain terms, this means a software component does not properly handle the amount of data it receives. By sending more data than the memory space is designed to hold, an attacker can corrupt surrounding memory, potentially leading to unauthorized control or system instability.

How can an attacker trigger this vulnerability?

This flaw is triggered by sending specially crafted data packets to the affected software component over a network. It is important to note that this requires no user interaction or prior authentication; however, the bug does not trigger if the network path to the HPLIP service is blocked or inaccessible.

Do I need to worry about this if my printer is internal?

According to Halo Surface Signal, HPLIP is generally used for local systems and is not designed to be exposed to the public internet. If your systems are confined to an internal network without external access, the likelihood of a remote exploit is significantly reduced compared to internet-facing infrastructure.

When should I update my HPLIP software?

You should prioritize updates if your Linux systems run versions earlier than 3.26.6. Start by auditing your environment to locate all installations of HPLIP, then verify which systems are reachable over the network to coordinate patching with the relevant system owners.

References