CVE-2026-89084: CWE-22 in HP Inc HP AC Print & Scan
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-89084) affects the HP Advance software within HP AC Print & Scan. It is classified as CWE-22, a path traversal issue, which can enable attackers to perform elevation of privilege, remote code execution, or arbitrary file writes on the server hosting the software. The CVSS 4.0 vector indicates the attack requires no privileges and no user interaction, with high impact on confidentiality and availability. The vulnerability is published and assigned by HP but lacks explicit patch or remediation details in the provided data.
Potential Impact
Successful exploitation could allow an unauthenticated attacker to gain elevated privileges, execute arbitrary code remotely, or write arbitrary files on the HP Advance server. This could compromise the confidentiality, integrity, and availability of the affected system. No known active exploitation has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or workaround information is provided, users should monitor HP's official advisories for updates. No specific mitigation steps can be recommended without vendor guidance.
CVE-2026-89084: CWE-22 in HP Inc HP AC Print & Scan
Description
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.
CVSS v4.0
Score 8.8high
Affected software
HP Inc
HP AC Print & Scan
HP Inc
HP Output Central
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-89084) affects the HP Advance software within HP AC Print & Scan. It is classified as CWE-22, a path traversal issue, which can enable attackers to perform elevation of privilege, remote code execution, or arbitrary file writes on the server hosting the software. The CVSS 4.0 vector indicates the attack requires no privileges and no user interaction, with high impact on confidentiality and availability. The vulnerability is published and assigned by HP but lacks explicit patch or remediation details in the provided data.
Potential Impact
Successful exploitation could allow an unauthenticated attacker to gain elevated privileges, execute arbitrary code remotely, or write arbitrary files on the HP Advance server. This could compromise the confidentiality, integrity, and availability of the affected system. No known active exploitation has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or workaround information is provided, users should monitor HP's official advisories for updates. No specific mitigation steps can be recommended without vendor guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hp
- Date Reserved
- 2026-09-10T19:43:51.079Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aaaf94655bf5e2cf51ba050
Added to database: 09/16/2026, 20:17:10 UTC
Last enriched: 09/16/2026, 20:31:30 UTC
Last updated: 09/17/2026, 04:39:37 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.