CVE-2026-12555

Published Aug 24, 2026

Last updated 17 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-12555 is a privilege escalation vulnerability found in HP Easy Start for macOS, affecting versions prior to 2.16.7.260722. This flaw, categorized under CWE-379 (Creation of Temporary File in Directory with Insecure Permissions), stems from the HP Easy Start Uninstaller component utilizing predictable, world-writable paths for temporary files while operating with administrative privileges. A local attacker can exploit this by creating symbolic links at these insecure temporary file locations before the privileged process starts. When the uninstaller accesses these paths, it may follow the attacker-controlled symlink, leading to privileged file modification or corruption, such as appending application-generated log data to an attacker-chosen target. HP has released updated software to address this issue.

Description
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Source
hp-security-alert@hp.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

hp-security-alert@hp.com
CWE-379

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10