Back to Intelligence

Fedora 44 hplip Update Patches 8 CVEs (CVE-2026-91097 to CVE-2026-91105): Unauthenticated RCE and Privilege Escalation — Detection and Remediation Guide

SA
Security Arsenal Team
October 3, 2026
9 min read

Fedora has shipped an important security update for the hplip package — HP's Linux Imaging and Printing suite — in Fedora 44. The update to hplip 3.26.6 resolves eight distinct vulnerabilities: CVE-2026-91097, CVE-2026-91098, CVE-2026-91099, CVE-2026-91100, CVE-2026-91101, CVE-2026-91102, CVE-2026-91103, and CVE-2026-91105. Per the Fedora advisory (FEDORA-2026-9e80aed94f), the flaw class includes unauthenticated code execution and unauthorized privilege gain — the two impact categories that should immediately move any printing-stack vulnerability to the top of your patch queue.

Print infrastructure is one of the most consistently neglected attack surfaces in enterprise Linux environments. HPLIP ships with network-facing daemons, CUPS backends, D-Bus service bindings, and helper utilities that run with elevated privileges — exactly the components attackers chain together to go from an unauthenticated network position to root on a workstation or print server. If you run Fedora 44 (or manage mixed fleets where hplip is deployed for HP printer support), treat this as a priority remediation.

Technical Analysis

Affected Products and Versions

  • Product: hplip (HP Linux Imaging and Printing)
  • Affected platform: Fedora 44 (all architectures shipping the hplip, hplip-gui, and libsane-hpaio packages)
  • Fixed version: hplip 3.26.6
  • Advisory: FEDORA-2026-9e80aed94f

CVEs Addressed

The 3.26.6 update fixes the following identifiers:

  • CVE-2026-91097
  • CVE-2026-91098
  • CVE-2026-91099
  • CVE-2026-91100
  • CVE-2026-91101
  • CVE-2026-91102
  • CVE-2026-91103
  • CVE-2026-91105

The advisory clusters these under unauthenticated code execution and unauthorized privilege gain. Practically, this maps to two exploitation paths defenders must understand:

  1. Network-reachable code execution. HPLIP's device communication layer (the hp: CUPS backend, hpcups, and associated I/O libraries) processes data from network printers over ports such as 9100/9101 (JetDirect) and SNMP-based device discovery. Memory corruption or command injection in that parsing path is exploitable by an attacker on the same network segment — or by a malicious/compromised printer — with no credentials required.
  2. Local privilege escalation. HPLIP installs D-Bus-activated services and helper tools that bridge the unprivileged user session to privileged printing operations (the CUPS lp group, backend execution as root via cupsd). Flaws in input validation across that privilege boundary allow a local user — or code running as the lp service account after exploiting path #1 — to escalate to root.

Chained together, these two primitives constitute full unauthenticated remote compromise of the host. This is the same structural pattern we've seen exploited in print-stack vulnerabilities across the industry for years, and it is why print services warrant the same scrutiny as web-facing services.

Exploitation Status

At the time of publication, the Fedora advisory does not indicate confirmed in-the-wild exploitation, and none of these CVEs have been listed in CISA's Known Exploited Vulnerabilities catalog. However, printing-stack bugs with unauthenticated RCE impact are historically rapid targets for proof-of-concept development once patches ship and diffs become available. The window between advisory and weaponization for this vulnerability class is typically measured in days to weeks — patch before the PoCs land.

Detection & Response

For defenders, the highest-fidelity signals are (a) the hplip/CUPS backend processes spawning unexpected child processes — a canonical indicator of successful exploitation of the backend — and (b) anomalous network traffic to raw printing ports. The following detections target Linux endpoints via auditd/sysmon-for-linux/Syslog telemetry ingested into Sentinel, plus endpoint hunting with Velociraptor.

YAML
---
title: HPLIP or CUPS Backend Spawning Shell or Command Interpreter
id: 3f8c2a91-6d4e-4b7a-9c01-2e5f7a8b9d21
status: experimental
description: Detects the hplip hp backend, hpcups filter, or cupsd spawning a shell or scripting interpreter — a strong indicator of exploitation of the print backend for code execution (e.g., CVE-2026-91097/CVE-2026-91105 class flaws).
references:
  - https://linuxsecurity.com/advisories/fedora/hplip-fedora-2026-9e80aed94f
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/06/10
tags:
  - attack.execution
  - attack.t1059.004
  - attack.exploitation_for_client_execution
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/hp'
      - '/hpcups'
      - '/cupsd'
      - '/hp-systray'
      - '/hp-toolbox'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/dash'
      - '/zsh'
      - '/python'
      - '/python3'
      - '/perl'
      - '/nc'
      - '/ncat'
      - '/wget'
      - '/curl'
  condition: selection_parent and selection_child
falsepositives:
  - Rare; legitimate CUPS filter chains invoke interpreters only via defined PPD filter scripts — investigate any occurrence
level: high
---
title: Suspicious Connection to Raw Print Ports Followed by Local Process Execution
id: 9b1e4d62-7a3c-48f5-b2d8-4c6e9f1a2537
status: experimental
description: Detects inbound network connections to JetDirect/raw print ports (9100-9101) accepted by a process that is not the expected cupsd/print service, which may indicate interception or exploitation attempts against the HPLIP network stack.
references:
  - https://linuxsecurity.com/advisories/fedora/hplip-fedora-2026-9e80aed94f
  - https://attack.mitre.org/techniques/T1200/
author: Security Arsenal
date: 2026/06/10
tags:
  - attack.initial_access
  - attack.t1200
  - attack.exploitation_of_remote_services
logsource:
  category: network_connection
  product: linux
detection:
  selection_port:
    DestinationPort:
      - 9100
      - 9101
  selection_exclude:
    Image|endswith:
      - '/cupsd'
      - '/cups-browsed'
  condition: selection_port and not selection_exclude
falsepositives:
  - Dedicated print server appliances or alternative print daemons; baseline per host role
level: medium
---
title: Privileged HPLIP Helper Executed by Unprivileged User Context
id: 5d7f2b48-1c9a-4e6d-a3b7-8f2c4d6e9a13
status: experimental
description: Detects execution of HPLIP privileged helper utilities or D-Bus activated hplip services with command lines indicative of privilege abuse, such as file writes to sensitive paths or user/group manipulation — consistent with unauthorized privilege gain via the hplip local attack surface.
references:
  - https://linuxsecurity.com/advisories/fedora/hplip-fedora-2026-9e80aed94f
  - https://attack.mitre.org/techniques/T1068/
author: Security Arsenal
date: 2026/06/10
tags:
  - attack.privilege_escalation
  - attack.t1068
logsource:
  category: process_creation
  product: linux
detection:
  selection_img:
    Image|contains:
      - '/hplip/'
      - '/hp-setup'
      - '/hp-plugin'
      - '/hp-check'
  selection_flags:
    CommandLine|contains:
      - '/etc/passwd'
      - '/etc/sudoers'
      - 'chmod u+s'
      - 'setuid'
      - 'cap_setuid'
      - '/root/'
      - 'useradd'
      - 'usermod'
  condition: all of selection_*
falsepositives:
  - Legitimate hp-plugin installation performs some privileged operations; correlate with package manager activity
level: high
KQL — Microsoft Sentinel / Defender
// Hunt: child processes spawned by HPLIP/CUPS backend components across the Linux fleet
// Requires Syslog, auditd, or Defender for Endpoint process telemetry in Sentinel
union isfuzzy=true
    (DeviceProcessEvents
    | where TimeGenerated > ago(7d)
    | where InitiatingProcessFileName has_any ("hp", "hpcups", "cupsd", "hp-systray", "hp-toolbox")
    | where FileName in~ ("bash", "sh", "dash", "zsh", "python", "python3", "perl", "nc", "ncat", "wget", "curl")
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName),
    (Syslog
    | where TimeGenerated > ago(7d)
    | where Facility == "cron" or ProcessName has_any ("cupsd", "hp", "hpcups")
    | where SyslogMessage has_any ("bash", "/bin/sh", "python", "nc ", "wget", "curl")
    | project TimeGenerated, HostName, ProcessName, SyslogMessage)
| order by TimeGenerated desc
KQL — Microsoft Sentinel / Defender
// Hunt: network connections to raw print ports from unexpected sources
// Useful for identifying scanning or exploitation attempts against the HPLIP network attack surface
CommonSecurityLog
| where TimeGenerated > ago(7d)
| where DestinationPort in (9100, 9101)
| summarize ConnectionCount = count(), DistinctSources = dcount(SourceIP), SourceIPs = make_set(SourceIP, 25) by DestinationIP, DestinationPort, bin(TimeGenerated, 1h)
| where DistinctSources > 3 or ConnectionCount > 100
| order by ConnectionCount desc
VQL — Velociraptor
-- Hunt for suspicious child processes of HPLIP/CUPS components and verify hplip version
-- Deploy as a multi-host hunt across Fedora endpoints

-- Part 1: Process ancestry check
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ 'bash|/bin/sh|python|perl|nc |ncat|wget|curl'
  AND Username =~ 'lp|root'

-- Part 2: Verify installed hplip version (flag anything below 3.26.6)
SELECT * FROM execve(argv=['rpm', '-q', 'hplip', '--queryformat', '%{NAME}-%{VERSION}-%{RELEASE}\n'])
Bash / Shell
#!/bin/bash
# hplip CVE remediation & verification script — Fedora 44
# Addresses CVE-2026-91097/098/099/100/101/102/103/105 via hplip 3.26.6

set -euo pipefail

echo "=== Current hplip version ==="
rpm -q hplip || { echo "hplip not installed — no action required"; exit 0; }

CURRENT=$(rpm -q hplip --queryformat '%{VERSION}')
echo "Installed: $CURRENT | Fixed: 3.26.6"

# Apply the security update
echo "=== Applying update ==="
dnf upgrade -y --refresh hplip hplip-common hplip-gui libsane-hpaio

NEW=$(rpm -q hplip --queryformat '%{VERSION}')
echo "Post-update version: $NEW"

# Verify the fixed version is installed
if [[ "$(printf '%s\n' "3.26.6" "$NEW" | sort -V | head -n1)" == "3.26.6" ]]; then
    echo "[PASS] hplip is at or above 3.26.6"
else
    echo "[FAIL] hplip $NEW is still below 3.26.6 — investigate repo mirrors"
    exit 1
fi

# Restart affected services to ensure patched binaries are loaded
echo "=== Restarting print services ==="
systemctl restart cups.service || true

# Hardening: confirm print services are not exposed beyond the LAN needlessly
echo "=== Exposure check: listening print ports ==="
ss -tlnp | grep -E ':(9100|9101|631)' || echo "No raw print ports listening (good)"

echo "=== Quick anomaly check: shells under lp/root spawned recently ==="
journalctl _COMM=cupsd --since "7 days ago" | grep -Ei 'bash|/bin/sh|python|nc |wget|curl' || echo "No suspicious backend child activity in journal"

echo "=== Done. Reboot recommended if hplip libraries are in use by long-running sessions ==="

Remediation

  1. Patch immediately. Update to hplip 3.26.6 on all Fedora 44 systems: sudo dnf upgrade hplip hplip-common hplip-gui libsane-hpaio --refresh Restart cups.service afterward, and reboot workstations where hplip GUI components (hp-systray) run in user sessions, so patched libraries are loaded everywhere.
  2. Inventory first. Many teams don't know where hplip is installed. Query your fleet (rpm -q hplip) via your configuration management or EDR. Remove the package entirely from systems that don't manage HP devices — the best remediation for unused attack surface is deletion.
  3. Reduce network exposure. Block inbound access to ports 9100/9101 and restrict 631 (IPP) to authorized print subnets via firewalld/NFTables. Unauthenticated RCE classes lose most of their bite when the service isn't reachable from arbitrary network positions.
  4. Segment printers. Printers should live on a dedicated VLAN with no lateral reachability to workstation or server segments — this also constrains the malicious-printer attack vector against the hplip parsing stack.
  5. Harden the privilege boundary. Audit which users are in the lp and lpadmin groups; remove unnecessary memberships. Monitor D-Bus policy for hplip services.
  6. Watch for post-patch PoCs. Diff-based exploit development against freshly patched print-stack CVEs is a well-worn pattern. Subscribe to the Fedora announce list and monitor the advisory page for updates, CVSS assignments, and any CISA KEV additions.

The print stack is not a peripheral concern — it is a privileged, network-facing subsystem on nearly every Linux endpoint. Organizations that treat hplip updates with the same urgency as browser or kernel patches will close this window before attackers step through it.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.