CVE-2026-91100

Description

A flaw was found in HP Linux Imaging and Printing (HPLIP) Software. Multiple vulnerabilities in several software components could allow a remote attacker to execute arbitrary code, escalate privileges, or cause a denial of service. Additionally, these flaws could lead to information disclosure or unauthorized file modification under certain conditions.

Mitigation

If HP printer support is not required on the system, remove the HPLIP package to eliminate the attack surface. For Red Hat Enterprise Linux, use `sudo dnf remove hplip`. Removing this package will disable functionality for HP printers.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.6N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredNoneN/AN/A
User InteractionRequiredN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityLowN/AN/A
Integrity ImpactHighN/AN/A
Availability ImpactLowN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.