<Vulnerability name="CVE-2026-91097">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-16T18:39:12</PublicDate>
    <Bugzilla id="2535607" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535607" xml:lang="en:us">
hplip: HPLIP: Multiple vulnerabilities enable remote code execution and privilege escalation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-94</CWE>
    <Details xml:lang="en:us" source="Mitre">
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in HPLIP (HP Linux Imaging and Printing) software. Multiple vulnerabilities exist that could allow a remote attacker to execute arbitrary code, escalate privileges, cause a denial of service, disclose sensitive information, or modify files without authorization. These issues arise under specific, unspecified conditions.
    </Details>
    <Mitigation xml:lang="en:us">
To mitigate this issue, if HPLIP functionality is not required, consider removing the `hplip` package. This can be done using the following command:

`sudo dnf remove hplip`

Removing this package will disable HP printer support and related utilities.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Affected</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Affected</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Affected</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-91097
https://nvd.nist.gov/vuln/detail/CVE-2026-91097
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
    </References>
</Vulnerability>