Search
Find a vulnerability
Search criteria
62 vulnerabilities by HP Inc
CVE-2026-106177 (GCVE-0-2026-106177)
Vulnerability from nvd – Published: 2026-10-08 15:32 – Updated: 2026-10-09 03:55
VLAI
EPSS
VEX
Title
HP Sure Click Kernel Buffer Overflow
Summary
A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-08 00:00 UTC
CWE
- CWE-122 - Heap-based Buffer Overflow
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Sure Click Enterprise |
Affected:
0 , < 4.4.33
(custom)
|
|
| HP Inc | HP Wolf Security for Business |
Affected:
0 , < 4.4.33
(custom)
|
|
| HP Inc | HP Wolf Pro Security |
Affected:
0 , < 4.4.33
(custom)
|
|
| HP Inc | HP Wolf Pro Security Edition |
Affected:
0 , < 4.4.33
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-106177",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-08T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T03:55:52.322Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Sure Click Enterprise",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Wolf Security for Business",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Wolf Pro Security",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Wolf Pro Security Edition",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Julian Horoszkiewicz (Atos Threat Research Center)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.\u003c/p\u003e"
}
],
"value": "A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-122",
"description": "CWE-122: Heap-based Buffer Overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-08T16:00:38.312Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15759419-15759442-16/hpsbhf04157"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Sure Click Kernel Buffer Overflow",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-106177",
"datePublished": "2026-10-08T15:32:16.010Z",
"dateReserved": "2026-10-06T16:28:52.187Z",
"dateUpdated": "2026-10-09T03:55:52.322Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84900 (GCVE-0-2026-84900)
Vulnerability from nvd – Published: 2026-10-05 20:28 – Updated: 2026-10-06 13:57
VLAI
EPSS
VEX
Title
HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates
Summary
Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities.
Previous versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 13:57 UTC
CWE
- CWE-354 - Improper validation of integrity check value
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1573599… | vendor-advisory |
| https://support.hp.com/us-en/document/ish_1573609… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | ThinPro 8.1 |
Affected:
0 , < ThinPro 8.1 SP10
(custom)
|
|
| HP Inc | ThinPro 9 |
Affected:
0 , < ThinPro 9 SP3
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84900",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T13:57:40.682017Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T13:57:48.597Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "ThinPro 8.1",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "ThinPro 8.1 SP10",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "ThinPro 9",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "ThinPro 9 SP3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Darren McDonald / AmberWolf"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities.\u0026nbsp;\u003cdiv\u003e\u003cbr\u003e\u003cdiv\u003ePrevious versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities.\u003c/div\u003e\u003c/div\u003e"
}
],
"value": "Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities.\u00a0\nPrevious versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "PHYSICAL",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-354",
"description": "CWE-354 Improper validation of integrity check value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-05T20:37:46.833Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15735991-15736015-16/hpsbhf04155"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15736095-15736118-16/hpsbhf04154"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-84900",
"datePublished": "2026-10-05T20:28:48.572Z",
"dateReserved": "2026-09-02T15:15:29.572Z",
"dateUpdated": "2026-10-06T13:57:48.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19915 (GCVE-0-2026-19915)
Vulnerability from nvd – Published: 2026-09-22 14:57 – Updated: 2026-09-29 16:07
VLAI
EPSS
VEX
Title
HP Support Assistant - Local Escalation of Privilege
Summary
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 03:55 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1567718… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Support Assistant |
Affected:
0 , < <9.55.10.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19915",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T03:55:52.051946Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T16:07:24.105Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP Support Assistant",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c9.55.10.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Naor of Novee Security"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"value": "A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:57:28.834Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15677182-15677204-16/hpsbgn04141"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Support Assistant - Local Escalation of Privilege",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-19915",
"datePublished": "2026-09-22T14:57:28.834Z",
"dateReserved": "2026-08-14T21:39:59.428Z",
"dateUpdated": "2026-09-29T16:07:24.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89084 (GCVE-0-2026-89084)
Vulnerability from nvd – Published: 2026-09-16 19:54 – Updated: 2026-09-17 16:06
VLAI
EPSS
VEX
Title
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Summary
HP
has identified potential security vulnerabilities in the HP Advance software
that may enable elevation of privilege, remote code execution, or arbitrary
file write under certain conditions, impacting the HP Advance server hosting
the software.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 16:06 UTC
CWE
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP AC Print & Scan |
Affected:
0 , < <V1R4.0.027
(custom)
|
|
| HP Inc | HP Output Central |
Affected:
0 , < <V1R4.0.029
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89084",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T16:06:15.678076Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:06:27.428Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP AC Print \u0026 Scan",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.027",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Output Central",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.029",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joseph Chiarchiaro, Independent Security Researcher"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eHP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software.\u003c/p\u003e"
}
],
"value": "HP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:54:52.408Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Advance \u2013 Potential Elevation of Privilege, Remote Code Execution \u0026 Arbitrary File Write",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-89084",
"datePublished": "2026-09-16T19:54:52.408Z",
"dateReserved": "2026-09-10T19:43:51.079Z",
"dateUpdated": "2026-09-17T16:06:27.428Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89083 (GCVE-0-2026-89083)
Vulnerability from nvd – Published: 2026-09-16 19:53 – Updated: 2026-09-17 16:07
VLAI
EPSS
VEX
Title
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Summary
HP
has identified potential security vulnerabilities in the HP Advance software
that may enable elevation of privilege, remote code execution, or arbitrary
file write under certain conditions, impacting the HP Advance server hosting
the software.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 16:06 UTC
CWE
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP AC Print & Scan |
Affected:
0 , < <V1R4.0.027
(custom)
|
|
| HP Inc | HP Output Central |
Affected:
0 , < <V1R4.0.029
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89083",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T16:06:48.772710Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:07:02.087Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP AC Print \u0026 Scan",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.027",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Output Central",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.029",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joseph Chiarchiaro, Independent Security Researcher"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eHP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software.\u003c/p\u003e"
}
],
"value": "HP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:53:06.331Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Advance \u2013 Potential Elevation of Privilege, Remote Code Execution \u0026 Arbitrary File Write",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-89083",
"datePublished": "2026-09-16T19:53:06.331Z",
"dateReserved": "2026-09-10T19:43:49.904Z",
"dateUpdated": "2026-09-17T16:07:02.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89082 (GCVE-0-2026-89082)
Vulnerability from nvd – Published: 2026-09-16 19:50 – Updated: 2026-09-17 16:08
VLAI
EPSS
VEX
Title
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Summary
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 16:07 UTC
CWE
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP AC Print & Scan |
Affected:
0 , < <V1R4.0.027
(custom)
|
|
| HP Inc | HP Output Central |
Affected:
0 , < <V1R4.0.029
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89082",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T16:07:50.103471Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:08:03.733Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP AC Print \u0026 Scan",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.027",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Output Central",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.029",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joseph Chiarchiaro, Independent Security Researcher"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software."
}
],
"value": "HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:50:40.614Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Advance \u2013 Potential Elevation of Privilege, Remote Code Execution \u0026 Arbitrary File Write",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-89082",
"datePublished": "2026-09-16T19:50:40.614Z",
"dateReserved": "2026-09-10T19:43:49.343Z",
"dateUpdated": "2026-09-17T16:08:03.733Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82346 (GCVE-0-2026-82346)
Vulnerability from nvd – Published: 2026-08-31 20:35 – Updated: 2026-08-31 20:53
VLAI
EPSS
VEX
Title
HP ImageDiags - Potential Escalation of Privilege
Summary
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-31 20:53 UTC
CWE
- CWE-379 - Creation of Temporary File in Directory with Insecure Permissions
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP ImageDiags |
Affected:
5.0.0.0 , < <5.0.0.36
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82346",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T20:53:42.939965Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T20:53:49.878Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP ImageDiags",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c5.0.0.36",
"status": "affected",
"version": "5.0.0.0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "benzdeus (Thinnawarth Mathuros)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"value": "A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-379",
"description": "CWE-379: Creation of Temporary File in Directory with Insecure Permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T20:35:39.046Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15572821-15572929-16/hpsbgn04143"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP ImageDiags - Potential Escalation of Privilege",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-82346",
"datePublished": "2026-08-31T20:35:39.046Z",
"dateReserved": "2026-08-28T16:42:02.512Z",
"dateUpdated": "2026-08-31T20:53:49.878Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-12556 (GCVE-0-2026-12556)
Vulnerability from nvd – Published: 2026-08-24 16:01 – Updated: 2026-09-03 15:17
VLAI
EPSS
VEX
Title
HP Easy Start for macOS - Security Update
Summary
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 03:56 UTC
CWE
- CWE-319 - Cleartext transmission of sensitive information
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1551234… | vendor-advisory |
| https://ciphersecuritylabs.com/papers/rooted-in-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Easy Start for macOS |
Affected:
0 , < <2.16.7.260722
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12556",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T03:56:49.406116Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T16:24:51.060Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"MacOS"
],
"product": "HP Easy Start for macOS",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c2.16.7.260722",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nir Yehoshua"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319 Cleartext transmission of sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T15:17:21.554Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Easy Start for macOS - Security Update",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-12556",
"datePublished": "2026-08-24T16:01:58.193Z",
"dateReserved": "2026-06-17T19:59:50.415Z",
"dateUpdated": "2026-09-03T15:17:21.554Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-12555 (GCVE-0-2026-12555)
Vulnerability from nvd – Published: 2026-08-24 16:00 – Updated: 2026-09-03 15:13
VLAI
EPSS
VEX
Title
HP Easy Start for macOS - Security Update
Summary
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 03:56 UTC
CWE
- CWE-379 - Creation of temporary file in directory with insecure permissions
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1551234… | vendor-advisory |
| https://ciphersecuritylabs.com/papers/rooted-in-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Easy Start for macOS |
Affected:
0 , < 2.16.7.260722
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12555",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T03:56:48.303782Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T16:24:51.227Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"MacOS"
],
"product": "HP Easy Start for macOS",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "2.16.7.260722",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nir Yehoshua"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-379",
"description": "CWE-379 Creation of temporary file in directory with insecure permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T15:13:15.889Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Easy Start for macOS - Security Update",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-12555",
"datePublished": "2026-08-24T16:00:23.156Z",
"dateReserved": "2026-06-17T19:59:49.335Z",
"dateUpdated": "2026-09-03T15:13:15.889Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-12554 (GCVE-0-2026-12554)
Vulnerability from nvd – Published: 2026-08-24 15:58 – Updated: 2026-09-03 15:16
VLAI
EPSS
VEX
Title
HP Easy Start for macOS - Security Update
Summary
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 03:56 UTC
CWE
- CWE-1104 - Use of unmaintained third party components
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1551234… | vendor-advisory |
| https://ciphersecuritylabs.com/papers/rooted-in-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Easy Start for macOS |
Affected:
0 , < 2.16.7.260722
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12554",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T03:56:47.074460Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T16:24:51.378Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"MacOS"
],
"product": "HP Easy Start for macOS",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "2.16.7.260722",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nir Yehoshua"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1104",
"description": "CWE-1104 Use of unmaintained third party components",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T15:16:52.890Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Easy Start for macOS - Security Update",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-12554",
"datePublished": "2026-08-24T15:58:29.333Z",
"dateReserved": "2026-06-17T19:59:48.123Z",
"dateUpdated": "2026-09-03T15:16:52.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75946 (GCVE-0-2026-75946)
Vulnerability from nvd – Published: 2026-08-21 13:50 – Updated: 2026-08-31 18:34
VLAI
EPSS
VEX
Title
OMEN Gaming Hub – Potential Escalation of Privilege & Information Disclosure
Summary
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 15:07 UTC
CWE
- CWE-347 - Improper verification of cryptographic signature
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | OMEN Gaming Hub |
Affected:
0 , < <1101.2608.0.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75946",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T15:07:49.464243Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T15:07:56.323Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "OMEN Gaming Hub",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c1101.2608.0.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Adrian Korwel (independent security researcher)"
},
{
"lang": "en",
"type": "finder",
"value": "QSearch Security Research"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"value": "A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper verification of cryptographic signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T18:34:58.616Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15491615-15491654-16/hpsbgn04144"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "OMEN Gaming Hub \u2013 Potential Escalation of Privilege \u0026 Information Disclosure",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-75946",
"datePublished": "2026-08-21T13:50:55.856Z",
"dateReserved": "2026-08-18T16:05:11.809Z",
"dateUpdated": "2026-08-31T18:34:58.616Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17639 (GCVE-0-2026-17639)
Vulnerability from nvd – Published: 2026-08-17 18:35 – Updated: 2026-08-17 18:59
VLAI
EPSS
VEX
Title
Certain HP Smart Tank All in One – Potential Denial of Service
Summary
Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-17 18:59 UTC
CWE
Assigner
References
1 reference
Impacted products
39 products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17639",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-17T18:59:12.636923Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T18:59:22.318Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5101 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5001 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5003 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5100 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5104 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5109 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5102 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5105 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5106 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5107 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5108 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5115 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 580 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 585 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 584 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 597 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 581 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 580 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 581 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 585 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 582 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 583 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 589 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 580 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 588 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 591 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 592 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 593 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 595 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 596 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 598 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 599 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5100 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5000 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5103 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 210 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 218 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 215 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 520 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 525 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 521 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 523 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 524 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 529 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests."
}
],
"value": "Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T18:35:32.360Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15407218-15407241-16/hpsbpi04142"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Certain HP Smart Tank All in One \u2013 Potential Denial of Service",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-17639",
"datePublished": "2026-08-17T18:35:32.360Z",
"dateReserved": "2026-07-27T21:41:44.586Z",
"dateUpdated": "2026-08-17T18:59:22.318Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18243 (GCVE-0-2026-18243)
Vulnerability from nvd – Published: 2026-08-03 15:58 – Updated: 2026-08-03 18:39
VLAI
EPSS
VEX
Title
HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)
Summary
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-03 18:39 UTC
CWE
- CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP DesignJet T3500 |
Affected:
0 , < AENEAS_04_09_09.1
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18243",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-03T18:39:11.151672Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T18:39:46.171Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP DesignJet T3500",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "AENEAS_04_09_09.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews."
}
],
"value": "Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T15:58:54.165Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15348281-15348304-16"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-18243",
"datePublished": "2026-08-03T15:58:54.165Z",
"dateReserved": "2026-07-29T14:16:27.551Z",
"dateUpdated": "2026-08-03T18:39:46.171Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-13753 (GCVE-0-2026-13753)
Vulnerability from nvd – Published: 2026-07-06 18:00 – Updated: 2026-08-31 21:22
VLAI
EPSS
VEX
Title
Certain HP DeskJet All in One – Potential Information Disclosure
Summary
Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-06 19:12 UTC
CWE
Assigner
References
2 references
Impacted products
55 products
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-13753",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-06T19:12:36.743111Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-06T19:12:56.542Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2026-07-06T19:33:52.015Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://www.kb.cert.org/vuls/id/828543"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2822 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2829 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2828 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2810 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2842e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2810e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2822e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2842e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2827e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2825e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DJ 4227e NA OOVWhite Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2842e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2855e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2852e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2874 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2876 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2878 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2879 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2878 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2876 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2877 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2879 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4925",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4927",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4928 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4925",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4926",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4977",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4929",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4929 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4928",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4978 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4975",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4976",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Plus 4220 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4221 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4227 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4228 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4220 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4252e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4258e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4255e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4258e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4220e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4222e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4230e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4210e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4276 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4278 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4275 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nguyen Tien Dung"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eCertain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.\u003c/p\u003e"
}
],
"value": "Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-703",
"description": "CWE-703",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T21:22:06.897Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15558834-15558856-16/hpsbpi04148"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Certain HP DeskJet All in One \u2013 Potential Information Disclosure",
"x_generator": {
"engine": "VINCE 3.0.43",
"env": "prod",
"origin": "https://cveawg.mitre.org/api/cve/CVE-2026-13753"
}
}
},
"cveMetadata": {
"assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"assignerShortName": "certcc",
"cveId": "CVE-2026-13753",
"datePublished": "2026-07-06T18:00:06.663Z",
"dateReserved": "2026-06-29T16:46:12.558Z",
"dateUpdated": "2026-08-31T21:22:06.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-2891 (GCVE-0-2026-2891)
Vulnerability from nvd – Published: 2026-07-01 14:08 – Updated: 2026-07-01 14:55
VLAI
EPSS
VEX
Title
Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
Summary
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-01 14:55 UTC
CWE
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-2891",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-01T14:55:44.071438Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T14:55:54.454Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CCX",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "9.50",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Trio C60",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "9.5.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Edge E",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "8.6.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T14:08:45.511Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15222895-15222917-16/hpsbpy04096"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Poly Voice Devices (CCX, Trio, Edge E) \u2013 Potential Denial of Service",
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-2891",
"datePublished": "2026-07-01T14:08:45.511Z",
"dateReserved": "2026-02-20T17:49:42.020Z",
"dateUpdated": "2026-07-01T14:55:54.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-106177 (GCVE-0-2026-106177)
Vulnerability from cvelistv5 – Published: 2026-10-08 15:32 – Updated: 2026-10-09 03:55
VLAI
EPSS
VEX
Title
HP Sure Click Kernel Buffer Overflow
Summary
A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.
Severity
6.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-08 00:00 UTC
CWE
- CWE-122 - Heap-based Buffer Overflow
Assigner
References
1 reference
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Sure Click Enterprise |
Affected:
0 , < 4.4.33
(custom)
|
|
| HP Inc | HP Wolf Security for Business |
Affected:
0 , < 4.4.33
(custom)
|
|
| HP Inc | HP Wolf Pro Security |
Affected:
0 , < 4.4.33
(custom)
|
|
| HP Inc | HP Wolf Pro Security Edition |
Affected:
0 , < 4.4.33
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-106177",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-08T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T03:55:52.322Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Sure Click Enterprise",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Wolf Security for Business",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Wolf Pro Security",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "HP Wolf Pro Security Edition",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "4.4.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Julian Horoszkiewicz (Atos Threat Research Center)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability.\u003c/p\u003e"
}
],
"value": "A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-122",
"description": "CWE-122: Heap-based Buffer Overflow",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-08T16:00:38.312Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15759419-15759442-16/hpsbhf04157"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Sure Click Kernel Buffer Overflow",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-106177",
"datePublished": "2026-10-08T15:32:16.010Z",
"dateReserved": "2026-10-06T16:28:52.187Z",
"dateUpdated": "2026-10-09T03:55:52.322Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84900 (GCVE-0-2026-84900)
Vulnerability from cvelistv5 – Published: 2026-10-05 20:28 – Updated: 2026-10-06 13:57
VLAI
EPSS
VEX
Title
HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates
Summary
Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities.
Previous versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 13:57 UTC
CWE
- CWE-354 - Improper validation of integrity check value
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1573599… | vendor-advisory |
| https://support.hp.com/us-en/document/ish_1573609… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | ThinPro 8.1 |
Affected:
0 , < ThinPro 8.1 SP10
(custom)
|
|
| HP Inc | ThinPro 9 |
Affected:
0 , < ThinPro 9 SP3
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84900",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T13:57:40.682017Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T13:57:48.597Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "ThinPro 8.1",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "ThinPro 8.1 SP10",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"platforms": [
"Linux"
],
"product": "ThinPro 9",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "ThinPro 9 SP3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Darren McDonald / AmberWolf"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities.\u0026nbsp;\u003cdiv\u003e\u003cbr\u003e\u003cdiv\u003ePrevious versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities.\u003c/div\u003e\u003c/div\u003e"
}
],
"value": "Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities.\u00a0\nPrevious versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "PHYSICAL",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-354",
"description": "CWE-354 Improper validation of integrity check value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-05T20:37:46.833Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15735991-15736015-16/hpsbhf04155"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15736095-15736118-16/hpsbhf04154"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-84900",
"datePublished": "2026-10-05T20:28:48.572Z",
"dateReserved": "2026-09-02T15:15:29.572Z",
"dateUpdated": "2026-10-06T13:57:48.597Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19915 (GCVE-0-2026-19915)
Vulnerability from cvelistv5 – Published: 2026-09-22 14:57 – Updated: 2026-09-29 16:07
VLAI
EPSS
VEX
Title
HP Support Assistant - Local Escalation of Privilege
Summary
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-23 03:55 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1567718… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Support Assistant |
Affected:
0 , < <9.55.10.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19915",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T03:55:52.051946Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T16:07:24.105Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP Support Assistant",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c9.55.10.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Naor of Novee Security"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"value": "A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T14:57:28.834Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15677182-15677204-16/hpsbgn04141"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Support Assistant - Local Escalation of Privilege",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-19915",
"datePublished": "2026-09-22T14:57:28.834Z",
"dateReserved": "2026-08-14T21:39:59.428Z",
"dateUpdated": "2026-09-29T16:07:24.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89084 (GCVE-0-2026-89084)
Vulnerability from cvelistv5 – Published: 2026-09-16 19:54 – Updated: 2026-09-17 16:06
VLAI
EPSS
VEX
Title
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Summary
HP
has identified potential security vulnerabilities in the HP Advance software
that may enable elevation of privilege, remote code execution, or arbitrary
file write under certain conditions, impacting the HP Advance server hosting
the software.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 16:06 UTC
CWE
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP AC Print & Scan |
Affected:
0 , < <V1R4.0.027
(custom)
|
|
| HP Inc | HP Output Central |
Affected:
0 , < <V1R4.0.029
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89084",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T16:06:15.678076Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:06:27.428Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP AC Print \u0026 Scan",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.027",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Output Central",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.029",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joseph Chiarchiaro, Independent Security Researcher"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eHP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software.\u003c/p\u003e"
}
],
"value": "HP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:54:52.408Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Advance \u2013 Potential Elevation of Privilege, Remote Code Execution \u0026 Arbitrary File Write",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-89084",
"datePublished": "2026-09-16T19:54:52.408Z",
"dateReserved": "2026-09-10T19:43:51.079Z",
"dateUpdated": "2026-09-17T16:06:27.428Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89083 (GCVE-0-2026-89083)
Vulnerability from cvelistv5 – Published: 2026-09-16 19:53 – Updated: 2026-09-17 16:07
VLAI
EPSS
VEX
Title
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Summary
HP
has identified potential security vulnerabilities in the HP Advance software
that may enable elevation of privilege, remote code execution, or arbitrary
file write under certain conditions, impacting the HP Advance server hosting
the software.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 16:06 UTC
CWE
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP AC Print & Scan |
Affected:
0 , < <V1R4.0.027
(custom)
|
|
| HP Inc | HP Output Central |
Affected:
0 , < <V1R4.0.029
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89083",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T16:06:48.772710Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:07:02.087Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP AC Print \u0026 Scan",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.027",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Output Central",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.029",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joseph Chiarchiaro, Independent Security Researcher"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eHP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software.\u003c/p\u003e"
}
],
"value": "HP\nhas identified potential security vulnerabilities in the HP Advance software\nthat may enable elevation of privilege, remote code execution, or arbitrary\nfile write under certain conditions, impacting the HP Advance server hosting\nthe software."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:53:06.331Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Advance \u2013 Potential Elevation of Privilege, Remote Code Execution \u0026 Arbitrary File Write",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-89083",
"datePublished": "2026-09-16T19:53:06.331Z",
"dateReserved": "2026-09-10T19:43:49.904Z",
"dateUpdated": "2026-09-17T16:07:02.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89082 (GCVE-0-2026-89082)
Vulnerability from cvelistv5 – Published: 2026-09-16 19:50 – Updated: 2026-09-17 16:08
VLAI
EPSS
VEX
Title
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write
Summary
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 16:07 UTC
CWE
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP AC Print & Scan |
Affected:
0 , < <V1R4.0.027
(custom)
|
|
| HP Inc | HP Output Central |
Affected:
0 , < <V1R4.0.029
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89082",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T16:07:50.103471Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:08:03.733Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP AC Print \u0026 Scan",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.027",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Output Central",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003cV1R4.0.029",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Joseph Chiarchiaro, Independent Security Researcher"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software."
}
],
"value": "HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T19:50:40.614Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Advance \u2013 Potential Elevation of Privilege, Remote Code Execution \u0026 Arbitrary File Write",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-89082",
"datePublished": "2026-09-16T19:50:40.614Z",
"dateReserved": "2026-09-10T19:43:49.343Z",
"dateUpdated": "2026-09-17T16:08:03.733Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82346 (GCVE-0-2026-82346)
Vulnerability from cvelistv5 – Published: 2026-08-31 20:35 – Updated: 2026-08-31 20:53
VLAI
EPSS
VEX
Title
HP ImageDiags - Potential Escalation of Privilege
Summary
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-31 20:53 UTC
CWE
- CWE-379 - Creation of Temporary File in Directory with Insecure Permissions
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP ImageDiags |
Affected:
5.0.0.0 , < <5.0.0.36
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82346",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T20:53:42.939965Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T20:53:49.878Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP ImageDiags",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c5.0.0.36",
"status": "affected",
"version": "5.0.0.0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "benzdeus (Thinnawarth Mathuros)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"value": "A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-379",
"description": "CWE-379: Creation of Temporary File in Directory with Insecure Permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T20:35:39.046Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15572821-15572929-16/hpsbgn04143"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP ImageDiags - Potential Escalation of Privilege",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-82346",
"datePublished": "2026-08-31T20:35:39.046Z",
"dateReserved": "2026-08-28T16:42:02.512Z",
"dateUpdated": "2026-08-31T20:53:49.878Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-12556 (GCVE-0-2026-12556)
Vulnerability from cvelistv5 – Published: 2026-08-24 16:01 – Updated: 2026-09-03 15:17
VLAI
EPSS
VEX
Title
HP Easy Start for macOS - Security Update
Summary
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 03:56 UTC
CWE
- CWE-319 - Cleartext transmission of sensitive information
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1551234… | vendor-advisory |
| https://ciphersecuritylabs.com/papers/rooted-in-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Easy Start for macOS |
Affected:
0 , < <2.16.7.260722
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12556",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T03:56:49.406116Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T16:24:51.060Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"MacOS"
],
"product": "HP Easy Start for macOS",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c2.16.7.260722",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nir Yehoshua"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319 Cleartext transmission of sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T15:17:21.554Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Easy Start for macOS - Security Update",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-12556",
"datePublished": "2026-08-24T16:01:58.193Z",
"dateReserved": "2026-06-17T19:59:50.415Z",
"dateUpdated": "2026-09-03T15:17:21.554Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-12555 (GCVE-0-2026-12555)
Vulnerability from cvelistv5 – Published: 2026-08-24 16:00 – Updated: 2026-09-03 15:13
VLAI
EPSS
VEX
Title
HP Easy Start for macOS - Security Update
Summary
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 03:56 UTC
CWE
- CWE-379 - Creation of temporary file in directory with insecure permissions
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1551234… | vendor-advisory |
| https://ciphersecuritylabs.com/papers/rooted-in-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Easy Start for macOS |
Affected:
0 , < 2.16.7.260722
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12555",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T03:56:48.303782Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T16:24:51.227Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"MacOS"
],
"product": "HP Easy Start for macOS",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "2.16.7.260722",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nir Yehoshua"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-379",
"description": "CWE-379 Creation of temporary file in directory with insecure permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T15:13:15.889Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Easy Start for macOS - Security Update",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-12555",
"datePublished": "2026-08-24T16:00:23.156Z",
"dateReserved": "2026-06-17T19:59:49.335Z",
"dateUpdated": "2026-09-03T15:13:15.889Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-12554 (GCVE-0-2026-12554)
Vulnerability from cvelistv5 – Published: 2026-08-24 15:58 – Updated: 2026-09-03 15:16
VLAI
EPSS
VEX
Title
HP Easy Start for macOS - Security Update
Summary
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 03:56 UTC
CWE
- CWE-1104 - Use of unmaintained third party components
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_1551234… | vendor-advisory |
| https://ciphersecuritylabs.com/papers/rooted-in-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP Easy Start for macOS |
Affected:
0 , < 2.16.7.260722
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-12554",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T03:56:47.074460Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T16:24:51.378Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"MacOS"
],
"product": "HP Easy Start for macOS",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "2.16.7.260722",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nir Yehoshua"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1104",
"description": "CWE-1104 Use of unmaintained third party components",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T15:16:52.890Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP Easy Start for macOS - Security Update",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-12554",
"datePublished": "2026-08-24T15:58:29.333Z",
"dateReserved": "2026-06-17T19:59:48.123Z",
"dateUpdated": "2026-09-03T15:16:52.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75946 (GCVE-0-2026-75946)
Vulnerability from cvelistv5 – Published: 2026-08-21 13:50 – Updated: 2026-08-31 18:34
VLAI
EPSS
VEX
Title
OMEN Gaming Hub – Potential Escalation of Privilege & Information Disclosure
Summary
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 15:07 UTC
CWE
- CWE-347 - Improper verification of cryptographic signature
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | OMEN Gaming Hub |
Affected:
0 , < <1101.2608.0.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75946",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T15:07:49.464243Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T15:07:56.323Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "OMEN Gaming Hub",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c1101.2608.0.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Adrian Korwel (independent security researcher)"
},
{
"lang": "en",
"type": "finder",
"value": "QSearch Security Research"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"value": "A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper verification of cryptographic signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T18:34:58.616Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15491615-15491654-16/hpsbgn04144"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "OMEN Gaming Hub \u2013 Potential Escalation of Privilege \u0026 Information Disclosure",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-75946",
"datePublished": "2026-08-21T13:50:55.856Z",
"dateReserved": "2026-08-18T16:05:11.809Z",
"dateUpdated": "2026-08-31T18:34:58.616Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17639 (GCVE-0-2026-17639)
Vulnerability from cvelistv5 – Published: 2026-08-17 18:35 – Updated: 2026-08-17 18:59
VLAI
EPSS
VEX
Title
Certain HP Smart Tank All in One – Potential Denial of Service
Summary
Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-17 18:59 UTC
CWE
Assigner
References
1 reference
Impacted products
39 products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17639",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-17T18:59:12.636923Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T18:59:22.318Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5101 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5001 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5003 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5100 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5104 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5109 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5102 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5105 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5106 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5107 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5108 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5115 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 580 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 585 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 584 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 597 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 581 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 580 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 581 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 585 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 582 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 583 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 589 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 580 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 588 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 591 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 592 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 593 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 595 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 596 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 598 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 599 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5100 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5000 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 5103 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 210 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 218 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 215 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2630C",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 520 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 525 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 521 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 523 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 524 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP Smart Tank 529 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "001.2622C or later",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests."
}
],
"value": "Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T18:35:32.360Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15407218-15407241-16/hpsbpi04142"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Certain HP Smart Tank All in One \u2013 Potential Denial of Service",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-17639",
"datePublished": "2026-08-17T18:35:32.360Z",
"dateReserved": "2026-07-27T21:41:44.586Z",
"dateUpdated": "2026-08-17T18:59:22.318Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-18243 (GCVE-0-2026-18243)
Vulnerability from cvelistv5 – Published: 2026-08-03 15:58 – Updated: 2026-08-03 18:39
VLAI
EPSS
VEX
Title
HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)
Summary
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-03 18:39 UTC
CWE
- CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| HP Inc | HP DesignJet T3500 |
Affected:
0 , < AENEAS_04_09_09.1
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18243",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-03T18:39:11.151672Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T18:39:46.171Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP DesignJet T3500",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "AENEAS_04_09_09.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews."
}
],
"value": "Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-03T15:58:54.165Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15348281-15348304-16"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-18243",
"datePublished": "2026-08-03T15:58:54.165Z",
"dateReserved": "2026-07-29T14:16:27.551Z",
"dateUpdated": "2026-08-03T18:39:46.171Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-13753 (GCVE-0-2026-13753)
Vulnerability from cvelistv5 – Published: 2026-07-06 18:00 – Updated: 2026-08-31 21:22
VLAI
EPSS
VEX
Title
Certain HP DeskJet All in One – Potential Information Disclosure
Summary
Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-06 19:12 UTC
CWE
Assigner
References
2 references
Impacted products
55 products
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-13753",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-06T19:12:36.743111Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-06T19:12:56.542Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2026-07-06T19:33:52.015Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://www.kb.cert.org/vuls/id/828543"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2822 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2829 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2828 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821 AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2810 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2842e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2820e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2810e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2821e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2822e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2823e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2842e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2827e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2825e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DJ 4227e NA OOVWhite Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2842e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2855e AIO Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 2852e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2874 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2876 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2878 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2875 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2879 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2878 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2876 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2877 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 2879 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4925",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4927",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4928 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4925",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4926",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4977",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4929",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4929 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4928",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4978 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4975",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage Ultra 4976",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Plus 4220 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4221 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4227 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4228 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4220 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4252e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4258e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4255e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4258e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4220e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4222e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4230e All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet 4210e All-in-One",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4276 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4278 All-in-One Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "HP DeskJet Ink Advantage 4275 Printer",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "\u003c001.2629A",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Nguyen Tien Dung"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eCertain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs.\u003c/p\u003e"
}
],
"value": "Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-703",
"description": "CWE-703",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T21:22:06.897Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15558834-15558856-16/hpsbpi04148"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Certain HP DeskJet All in One \u2013 Potential Information Disclosure",
"x_generator": {
"engine": "VINCE 3.0.43",
"env": "prod",
"origin": "https://cveawg.mitre.org/api/cve/CVE-2026-13753"
}
}
},
"cveMetadata": {
"assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
"assignerShortName": "certcc",
"cveId": "CVE-2026-13753",
"datePublished": "2026-07-06T18:00:06.663Z",
"dateReserved": "2026-06-29T16:46:12.558Z",
"dateUpdated": "2026-08-31T21:22:06.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-2891 (GCVE-0-2026-2891)
Vulnerability from cvelistv5 – Published: 2026-07-01 14:08 – Updated: 2026-07-01 14:55
VLAI
EPSS
VEX
Title
Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service
Summary
The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-01 14:55 UTC
CWE
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-2891",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-01T14:55:44.071438Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T14:55:54.454Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "CCX",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "9.50",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Trio C60",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "9.5.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Edge E",
"vendor": "HP Inc",
"versions": [
{
"lessThan": "8.6.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"value": "The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-01T14:08:45.511Z",
"orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"shortName": "hp"
},
"references": [
{
"url": "https://support.hp.com/us-en/document/ish_15222895-15222917-16/hpsbpy04096"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Poly Voice Devices (CCX, Trio, Edge E) \u2013 Potential Denial of Service",
"x_generator": {
"engine": "Vulnogram 1.0.2"
}
}
},
"cveMetadata": {
"assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
"assignerShortName": "hp",
"cveId": "CVE-2026-2891",
"datePublished": "2026-07-01T14:08:45.511Z",
"dateReserved": "2026-02-20T17:49:42.020Z",
"dateUpdated": "2026-07-01T14:55:54.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}