CVE-2026-12553

8.9

HP · Web Jetadmin

HP Web Jetadmin is susceptible to a DLL hijacking vulnerability that allows unauthenticated actors to read or write arbitrary files on the system.

Executive summary

HP Web Jetadmin versions prior to 10.6 are vulnerable to a DLL hijacking attack that could allow an unauthenticated attacker to achieve unauthorized file access and modification.

Vulnerability

The software contains an out-of-bounds write vulnerability (CWE-787) that is triggered through a DLL hijacking mechanism. This allows an unauthenticated attacker to interact with the file system, potentially leading to arbitrary read or write operations.

Business impact

The severity of this issue is high, with a CVSS score of 8.9 reflecting the potential for total technical impact, including unauthorized file system modification. Such access could lead to full system compromise, malware installation, or the theft of sensitive administrative data managed by Web Jetadmin.

Remediation

Immediate Action: Update HP Web Jetadmin to version 10.6 or later immediately to address the DLL hijacking vector.

Proactive Monitoring: Monitor for unexpected file modifications or the loading of unauthorized libraries within the Web Jetadmin installation directory.

Compensating Controls: Ensure the application is hosted in a hardened environment with strict file system permissions and restrict network access to the management interface.

Exploitation status

Public Exploit Available: No confirmed public exploit (exploit_available: false).

Analyst recommendation

This vulnerability represents a critical threat to administrative infrastructure. Given the high CVSS score and the potential for full system compromise, administrators must prioritize upgrading to version 10.6 or higher across all deployments immediately.

More HP CVEs