VULNARCHIVE

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)

Joe via Fulldisclosure ·

HP Advance / HP Output Central

CVE-2026-89082, CVE-2026-89083, CVE-2026-89084

================================================================
SUMMARY
================================================================

Vendor: HP Inc.
Product family named by HP: HP Advance
Products in HP's update table: HP AC Print & Scan; HP Output Central
Components: Drivve SecureScan, MFPsecure
Severity: two Critical (9.3), one High (8.8), CVSS 4.0
Confirmed on: V1R4.0.026

Vendor bulletin: HPSBPI04149 / PSR-2026-0126, published 2026-09-16
Researcher: Joseph Chiarchiaro, https://printoverrun.com







================================================================
[1] CVE-2026-89082 - 9.3 Critical
Unauthenticated archive path traversal leading to SYSTEM code execution
================================================================

Vulnerable component: Drivve SecureScan log-viewer web application
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HP CNA CWE: CWE-94
Researcher assessment: CWE-22, CWE-306





================================================================
[2] CVE-2026-89083 - 9.3 Critical
Forged-header bypass of a local-only authorization gate
================================================================

Vulnerable component: MFPsecure device-integration SOAP service
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N
HP CNA CWE: CWE-94
Researcher assessment: CWE-290, CWE-863







================================================================
[3] CVE-2026-89084 - 8.8 High
Unauthenticated .xml file write and deletion as SYSTEM
================================================================

Vulnerable component: MFPsecure device-integration SOAP service
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
HP CNA CWE: CWE-22
Additional researcher assessment: CWE-306





================================================================
AFFECTED VERSIONS AND REMEDIATION
================================================================

The underlying behavior for all three findings was confirmed on V1R4.0.026.

HP's security bulletin lists the following updated R4 versions:

- HP AC Print & Scan: V1R4.0.027 or later
- HP Output Central: V1R4.0.029









================================================================
MITIGATION
================================================================





The affected paths themselves require no authentication.

================================================================
DISCLOSURE TIMELINE
================================================================

2026-06-01 Reported to HP PSRT.
2026-06-24 All three reported root behaviors confirmed on V1R4.0.026.

2026-07-21 HP validated the findings; fixes in progress.
2026-09-14 CVE assignments and CVSS scores communicated by HP.
2026-09-16 HP security bulletin and researcher advisories published.

================================================================
TECHNICAL DETAILS
================================================================





================================================================
REFERENCES
================================================================

HP Security Bulletin HPSBPI04149 / PSR-2026-0126:
https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149

CVE-2026-89082:
https://printoverrun.com/disclosures/cve-2026-89082/
https://www.cve.org/CVERecord?id=CVE-2026-89082

CVE-2026-89083:
https://printoverrun.com/disclosures/cve-2026-89083/
https://www.cve.org/CVERecord?id=CVE-2026-89083

CVE-2026-89084:
https://printoverrun.com/disclosures/cve-2026-89084/
https://www.cve.org/CVERecord?id=CVE-2026-89084

================================================================

CVE assignment and CVSS scoring: HP Inc. as CNA.
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/