HP Advance / HP Output CentralUnauthenticated SYSTEM RCE, authorization bypass, and arbitrary file write/delete
CVE-2026-89082, CVE-2026-89083, CVE-2026-89084 ================================================================ SUMMARY ================================================================ Vendor: HP Inc. Product family named by HP: HP Advance Products in HP's update table: HP AC Print & Scan; HP Output Central Components: Drivve SecureScan, MFPsecure Severity: two Critical (9.3), one High (8.8), CVSS 4.0 Confirmed on: V1R4.0.026HP-listed R4 updates: HP AC Print & Scan V1R4.0.027 or later; HP Output Central V1R4.0.029
Vendor bulletin: HPSBPI04149 / PSR-2026-0126, published 2026-09-16 Researcher: Joseph Chiarchiaro, https://printoverrun.comOn 16 September 2026, HP published a security bulletin and remediation information for three vulnerabilities I reported in the SecureScan and MFPsecure services used by HP Advance / HP Output Central.
All three vulnerabilities are reachable without credentials by a remote attacker with network access to the affected service. Two are rated Critical and one High under CVSS 4.0.
HP did not explicitly identify the finding-to-CVE mapping in its bulletin or CNA records. The mapping below is inferred from the three one-to-one CVSS vectors HP assigned, each of which exactly matches one of the reported findings.
================================================================ [1] CVE-2026-89082 - 9.3 Critical Unauthenticated archive path traversal leading to SYSTEM code execution ================================================================ Vulnerable component: Drivve SecureScan log-viewer web application CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N HP CNA CWE: CWE-94 Researcher assessment: CWE-22, CWE-306An unauthenticated archive-upload endpoint extracts archive entries without enforcing containment of their destination paths. An attacker can choose both the contents and destination of files outside the intended extraction directory, subject to the locations writable by the application pool, with no filename-extension restriction.
Remote code execution as NT AUTHORITY\SYSTEM was demonstrated end to end using a benign process-identity payload on a pristine V1R3.0.033 installation. The archive traversal and out-of-directory, web-readable write were separately reconfirmed on V1R4.0.026.
================================================================ [2] CVE-2026-89083 - 9.3 Critical Forged-header bypass of a local-only authorization gate ================================================================ Vulnerable component: MFPsecure device-integration SOAP service CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N HP CNA CWE: CWE-94 Researcher assessment: CWE-290, CWE-863Privileged operations rely on an attacker-forgeable HTTP header value to determine whether the caller is local. A remote attacker can supply the value expected for a local request and satisfy the authorization gate.
Testing demonstrated retrieval of a privileged Gateway API token, enumeration of directory users and groups, and setting attacker-chosen card and PIN values on a disposable test account in the Gateway credential store through the privileged API. Device login and directory write-back were not demonstrated.
Existing card and PIN values were redacted when queried through read operations.
================================================================ [3] CVE-2026-89084 - 8.8 High Unauthenticated .xml file write and deletion as SYSTEM ================================================================ Vulnerable component: MFPsecure device-integration SOAP service CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N HP CNA CWE: CWE-22 Additional researcher assessment: CWE-306An unauthenticated device-synchronization request uses caller-supplied values to construct filesystem paths without containment.
A remote attacker can create and delete .xml files at attacker-chosen paths within the permissions of the service account. Testing confirmed that the service was operating with SYSTEM privileges. Code execution was not demonstrated for this CVE.
================================================================ AFFECTED VERSIONS AND REMEDIATION ================================================================ The underlying behavior for all three findings was confirmed on V1R4.0.026. HP's security bulletin lists the following updated R4 versions: - HP AC Print & Scan: V1R4.0.027 or later - HP Output Central: V1R4.0.029I have not tested either updated build and therefore cannot independently confirm that the vulnerabilities are resolved in those versions.
CVE-2026-89082 and CVE-2026-89084 were also independently confirmed on HP Advance R3 V1R3.0.033.
No R3 fix has been identified in the remediation information available to me at publication. Operators of that build should therefore treat those two issues as unpatched and seek remediation guidance from HP.
The operations and authorization gate involved in CVE-2026-89083 were absent from the tested R3 build.
================================================================ MITIGATION ================================================================Apply the HP-listed R4 update appropriate to the installed product and verify that the affected behavior is no longer reachable.
Where operationally feasible, restrict inbound access to the affected SecureScan and MFPsecure interfaces to systems that require it. These interfaces also carry legitimate application traffic, however, so simple address- or port-based restrictions may interfere with required print or scan functionality and should not be considered a substitute for the vendor update.
The affected paths themselves require no authentication. ================================================================ DISCLOSURE TIMELINE ================================================================ 2026-06-01 Reported to HP PSRT. 2026-06-24 All three reported root behaviors confirmed on V1R4.0.026.2026-06-29 R3 applicability of CVE-2026-89082 and CVE-2026-89084 reported to HP.
2026-07-21 HP validated the findings; fixes in progress. 2026-09-14 CVE assignments and CVSS scores communicated by HP. 2026-09-16 HP security bulletin and researcher advisories published. ================================================================ TECHNICAL DETAILS ================================================================Reproduction code and other technical details are being withheld while the R3 remediation status remains unresolved.
The advisories may be expanded when R3 remediation becomes available or its support/remediation status is clarified.
================================================================ REFERENCES ================================================================ HP Security Bulletin HPSBPI04149 / PSR-2026-0126: https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149 CVE-2026-89082: https://printoverrun.com/disclosures/cve-2026-89082/ https://www.cve.org/CVERecord?id=CVE-2026-89082 CVE-2026-89083: https://printoverrun.com/disclosures/cve-2026-89083/ https://www.cve.org/CVERecord?id=CVE-2026-89083 CVE-2026-89084: https://printoverrun.com/disclosures/cve-2026-89084/ https://www.cve.org/CVERecord?id=CVE-2026-89084 ================================================================ CVE assignment and CVSS scoring: HP Inc. as CNA.
Attachment:
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/