---
id: CVE-2026-91104
title: >-
  HP has identified and remediated multiple externally reported vulnerabilities
  within HPLIP
summary: >-
  HP has identified and remediated multiple externally reported vulnerabilities
  within HPLIP. The findings affect several software components that could
  potentially enable remote code execution, privilege escalation, denial of
  service, inf…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: hp
product: linux_imaging_and_printing
affected:
  - linux_imaging_and_printing < 3.26.6
patched:
  - linux_imaging_and_printing 3.26.6
published: '2026-09-16'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:28:02.620'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91104'
references:
  - url: 'https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151'
    label: hp-security-alert@hp.com
tags:
  - nvd
  - cve.org
epss: 0.00964
epssPercentile: 0.6001
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-17T03:57:30.855235Z'
scores:
  nvd: 9.8
  cna: 9.3
ingestedAt: '2026-09-16T19:02:30.721Z'
---

## Overview

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

## Affected

- `linux_imaging_and_printing < 3.26.6`

## Remediation

Upgrade past the affected range:

- `linux_imaging_and_printing 3.26.6`
