{"id":"CVE-2026-91102","title":"HP has identified and remediated multiple externally reported vulnerabilities within HPLIP","summary":"HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78","CWE-494"],"vendor":"hp","product":"linux_imaging_and_printing","affected":["linux_imaging_and_printing < 3.26.6"],"patched":["linux_imaging_and_printing 3.26.6"],"published":"2026-09-16","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:28:16.553","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91102","references":[{"url":"https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151","label":"hp-security-alert@hp.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91102.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-91102"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535622"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-91102"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91102"}],"tags":["nvd","cve.org","csaf","vex","red-hat","score-dispute"],"epss":0.00246,"epssPercentile":0.16182,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-17T11:55:27.818472Z"},"scores":{"nvd":9.8,"cna":8.4,"vendor":7.8},"ingestedAt":"2026-09-16T19:02:30.722Z","slug":"CVE-2026-91102","body":"## Overview\n\nHP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.\n\n## Affected\n\n- `linux_imaging_and_printing < 3.26.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_imaging_and_printing 3.26.6`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91102.json)","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208628,"id":"CVE-2026-91102","ts":1790013042789,"field":"cvss","old":"8.4","new":"9.8"},{"seq":208627,"id":"CVE-2026-91102","ts":1790013042789,"field":"severity","old":"high","new":"critical"}]}