CVE-2026-89084
8.8HP · HP AC Print & Scan
HP Advance software is vulnerable to elevation of privilege, remote code execution, and arbitrary file write, potentially compromising the host server.
Executive summary
A critical vulnerability in HP Advance software allows unauthenticated remote attackers to execute arbitrary code or write files, posing a severe risk to server integrity.
Vulnerability
This vulnerability involves improper path validation (CWE-22) within the HP Advance software suite, which can be triggered by an unauthenticated attacker to achieve remote code execution or arbitrary file writes on the host server.
Business impact
The potential for remote code execution and arbitrary file write capabilities represents a total compromise of the affected server. With a CVSS score of 8.8, this flaw carries a high severity, as it allows attackers to gain full control over print and scan infrastructure, potentially leading to sensitive data exfiltration or lateral movement within the corporate network.
Remediation
Immediate Action: Administrators must update HP AC Print & Scan to version V1R4.0.027 or higher and HP Output Central to version V1R4.0.029 or higher immediately.
Proactive Monitoring: Security teams should monitor server access logs for unusual file write operations or unexpected process execution patterns originating from the HP Advance service.
Compensating Controls: Deploy Web Application Firewall rules to block unauthorized requests targeting the HP Advance web interface and restrict network access to the server to trusted internal segments only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for remote code execution, this vulnerability poses a significant threat to organizational security. IT administrators should prioritize the installation of the provided vendor patches across all affected HP Advance server instances to prevent unauthorized system access.
More HP CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Joseph Chiarchiaro, Independent Security Researcher, per the CVE Program record.