SUSE SLES12 Security Update : hplip (SUSE-SU-2026:4335-1)

critical Nessus Plugin ID 350137

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 / SLES_SAP12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4335-1 advisory.

- CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303).
- CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304).
- CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305).
- CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306).
- CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307).
- CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308).
- CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309).
- CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313).
- CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310).
- CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314 bsc#1282051).

Changes for hplip:

- Fix download of propietary plugin for 3.26.6
- Update to HPLIP 3.26.6
- Add support for the following new printers:
* HP ScanJet Enterprise Flow N9000 sn1
* HP ScanJet Enterprise Flow 9000 s1
* HP ScanJet Pro 4200 s1
* HP LaserJet Pro 4006dn printer
* HP LaserJet Pro 4006dw printer
* HP LaserJet Pro 4006n printer
* HP LaserJet Pro 4002d printer
* HP LaserJet Pro 4007dw printer
* HP LaserJet Pro 4007n printer
* HP LaserJet Pro 4008d
* HP LaserJet Pro 4008dn
* HP LaserJet Pro 4008dw
* HP LaserJet Pro MFP 4112dw printer
* HP LaserJet Pro MFP 4112fdn printer
* HP LaserJet Pro MFP 4112fdw printer
* HP LaserJet Pro MFP 4113dw printer
* HP LaserJet Pro MFP 4113dwg printer
* HP LaserJet Pro MFP 4113fdn printer
* HP LaserJet Pro MFP 4113fdng printer
* HP LaserJet Pro MFP 4113fdw printer
* HP LaserJet Pro MFP 4113fdwg printer
* HP LaserJet Pro MFP 4114dw
* HP LaserJet Pro MFP 4114fdn
* HP LaserJet Pro MFP 4114fdw

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1281303

https://bugzilla.suse.com/1281304

https://bugzilla.suse.com/1281305

https://bugzilla.suse.com/1281306

https://bugzilla.suse.com/1281307

https://bugzilla.suse.com/1281308

https://bugzilla.suse.com/1281309

https://bugzilla.suse.com/1281310

https://bugzilla.suse.com/1281313

https://bugzilla.suse.com/1281314

https://bugzilla.suse.com/1282051

https://www.suse.com/security/cve/CVE-2026-91097

https://www.suse.com/security/cve/CVE-2026-91098

https://www.suse.com/security/cve/CVE-2026-91099

https://www.suse.com/security/cve/CVE-2026-91100

https://www.suse.com/security/cve/CVE-2026-91101

https://www.suse.com/security/cve/CVE-2026-91102

https://www.suse.com/security/cve/CVE-2026-91103

https://www.suse.com/security/cve/CVE-2026-91104

https://www.suse.com/security/cve/CVE-2026-91105

https://www.suse.com/security/cve/CVE-2026-91106

http://www.nessus.org/u?5ca04618

Plugin Details

Severity: Critical

ID: 350137

File Name: suse_SU-2026-4335-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.29

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-91106

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:hplip-devel, p-cpe:/a:novell:suse_linux:hplip-hpijs, p-cpe:/a:novell:suse_linux:hplip-sane, p-cpe:/a:novell:suse_linux:hplip-udev-rules, p-cpe:/a:novell:suse_linux:hplip

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/24/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-91097, CVE-2026-91098, CVE-2026-91099, CVE-2026-91100, CVE-2026-91101, CVE-2026-91102, CVE-2026-91103, CVE-2026-91104, CVE-2026-91105, CVE-2026-91106

SuSE: SUSE-SU-2026:4335-1