<Vulnerability name="CVE-2026-91099">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-16T18:45:51</PublicDate>
    <Bugzilla id="2535600" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535600" xml:lang="en:us">
hplip: HPLIP: Multiple vulnerabilities enabling local code execution and privilege escalation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-266</CWE>
    <Details xml:lang="en:us" source="Mitre">
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in HPLIP (HP Linux Imaging and Printing) software. Multiple vulnerabilities exist in several software components that could potentially allow a local attacker to achieve local code execution, escalate privileges, cause a denial of service (DoS), disclose sensitive information, or modify files without authorization under certain conditions.
    </Details>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>hplip</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-91099
https://nvd.nist.gov/vuln/detail/CVE-2026-91099
https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151
    </References>
</Vulnerability>