Three critical and high-severity vulnerabilities have been disclosed in HP Advance and HP Output Central products, specifically affecting the Drivve SecureScan and MFPsecure components. The most severe flaw, tracked as CVE-2026-89082, is an unauthenticated archive path traversal vulnerability that enables remote code execution (RCE) with NT AUTHORITY\SYSTEM privileges. The other vulnerabilities include a local-only authorization gate bypass via forged HTTP headers (CVE-2026-89083) and unauthenticated arbitrary XML file manipulation (CVE-2026-89084).
HP has released security updates for version R4 of the affected products, but version R3 remains potentially vulnerable with no official fix identified at the time of publication. Cybersecurity analysts recommend that organizations using HP AC Print & Scan or HP Output Central apply the latest vendor updates immediately and restrict network access to the affected service interfaces to mitigate potential exploitation risks.
Top comments (0)