#1148269 hplip: CVE-2026-91097 CVE-2026-91098 CVE-2026-91099 CVE-2026-91100 CVE-2026-91101 CVE-2026-91102 CVE-2026-91103 CVE-2026-91104 CVE-2026-91105 CVE-2026-91106

Package:
src:hplip
Source:
src:hplip
Submitter:
Moritz Mühlenhoff
Date:
2026-09-18 17:29:03 UTC
Severity:
normal
Tags:
#1148269#5
Date:
2026-09-18 15:41:01 UTC
From:
To:
Hi,

The following vulnerabilities were published for hplip.

Another hplip release without more specific information other than
it being fixed in 3.26.6 and CVSS scores...

https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151


CVE-2026-91097[0]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91098[1]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91099[2]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91100[3]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91101[4]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91102[5]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91103[6]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91104[7]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91105[8]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.

CVE-2026-91106[9]:
| HP has identified and remediated multiple externally reported
| vulnerabilities within HPLIP. The findings affect several software
| components that could potentially enable remote code execution,
| privilege escalation, denial of service, information disclosure, or
| unauthorized file modification under certain conditions.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-91097
https://www.cve.org/CVERecord?id=CVE-2026-91097
[1] https://security-tracker.debian.org/tracker/CVE-2026-91098
https://www.cve.org/CVERecord?id=CVE-2026-91098
[2] https://security-tracker.debian.org/tracker/CVE-2026-91099
https://www.cve.org/CVERecord?id=CVE-2026-91099
[3] https://security-tracker.debian.org/tracker/CVE-2026-91100
https://www.cve.org/CVERecord?id=CVE-2026-91100
[4] https://security-tracker.debian.org/tracker/CVE-2026-91101
https://www.cve.org/CVERecord?id=CVE-2026-91101
[5] https://security-tracker.debian.org/tracker/CVE-2026-91102
https://www.cve.org/CVERecord?id=CVE-2026-91102
[6] https://security-tracker.debian.org/tracker/CVE-2026-91103
https://www.cve.org/CVERecord?id=CVE-2026-91103
[7] https://security-tracker.debian.org/tracker/CVE-2026-91104
https://www.cve.org/CVERecord?id=CVE-2026-91104
[8] https://security-tracker.debian.org/tracker/CVE-2026-91105
https://www.cve.org/CVERecord?id=CVE-2026-91105
[9] https://security-tracker.debian.org/tracker/CVE-2026-91106
https://www.cve.org/CVERecord?id=CVE-2026-91106

Please adjust the affected versions in the BTS as needed.