Vulnerability Intelligence Report
Hplip: incomplete fix for cve-2026-8631
CVE-2026-14544
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-190 ↗Integer Overflow or Wraparound
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| HP | HPLIP | 0 (affected) |
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.23.12-10.el10_2.5 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:3.18.4-14.el8_10 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.21.2-6.el9_8.5 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 6 | all |
| Red Hat | Red Hat Enterprise Linux 7 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.864%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2026-07-03T07:06:13 |
| Published | 2026-07-03T07:26:00 |
| Patch Date | 2026-07-03 |
| Last Updated | 2026-08-21T11:31:34 |
Community Chatter & Buzz