HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)
Joe via Fulldisclosure ·
HP Advance / HP Output Central CVE-2026-89082, CVE-2026-89083, CVE-2026-89084 ================================================================ SUMMARY ================================================================ Vendor: HP Inc. Product family named by HP: HP Advance Products in HP's update table: HP AC Print & Scan; HP Output Central Components: Drivve SecureScan, MFPsecure Severity: two Critical (9.3), one High (8.8), CVSS 4.0 Confirmed on: V1R4.0.026 Vendor bulletin: HPSBPI04149 / PSR-2026-0126, published 2026-09-16 Researcher: Joseph Chiarchiaro, https://printoverrun.com ================================================================ [1] CVE-2026-89082 - 9.3 Critical Unauthenticated archive path traversal leading to SYSTEM code execution ================================================================ Vulnerable component: Drivve SecureScan log-viewer web application CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N HP CNA CWE: CWE-94 Researcher assessment: CWE-22, CWE-306 ================================================================ [2] CVE-2026-89083 - 9.3 Critical Forged-header bypass of a local-only authorization gate ================================================================ Vulnerable component: MFPsecure device-integration SOAP service CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N HP CNA CWE: CWE-94 Researcher assessment: CWE-290, CWE-863 ================================================================ [3] CVE-2026-89084 - 8.8 High Unauthenticated .xml file write and deletion as SYSTEM ================================================================ Vulnerable component: MFPsecure device-integration SOAP service CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N HP CNA CWE: CWE-22 Additional researcher assessment: CWE-306 ================================================================ AFFECTED VERSIONS AND REMEDIATION ================================================================ The underlying behavior for all three findings was confirmed on V1R4.0.026. HP's security bulletin lists the following updated R4 versions: - HP AC Print & Scan: V1R4.0.027 or later - HP Output Central: V1R4.0.029 ================================================================ MITIGATION ================================================================ The affected paths themselves require no authentication. ================================================================ DISCLOSURE TIMELINE ================================================================ 2026-06-01 Reported to HP PSRT. 2026-06-24 All three reported root behaviors confirmed on V1R4.0.026. 2026-07-21 HP validated the findings; fixes in progress. 2026-09-14 CVE assignments and CVSS scores communicated by HP. 2026-09-16 HP security bulletin and researcher advisories published. ================================================================ TECHNICAL DETAILS ================================================================ ================================================================ REFERENCES ================================================================ HP Security Bulletin HPSBPI04149 / PSR-2026-0126: https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149 CVE-2026-89082: https://printoverrun.com/disclosures/cve-2026-89082/ https://www.cve.org/CVERecord?id=CVE-2026-89082 CVE-2026-89083: https://printoverrun.com/disclosures/cve-2026-89083/ https://www.cve.org/CVERecord?id=CVE-2026-89083 CVE-2026-89084: https://printoverrun.com/disclosures/cve-2026-89084/ https://www.cve.org/CVERecord?id=CVE-2026-89084 ================================================================ CVE assignment and CVSS scoring: HP Inc. as CNA. _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/