CVE-2026-12555
CVE-2026-12555 is a high-severity vulnerability with a CVSS 4.0 base score of 7.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-379.
Key facts
- Severity: High (CVSS 4.0 base score 7.7)
- EPSS exploit prediction: 0% (15th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-379
- Published:
- Last modified:
Description
Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
Frequently asked questions
- What is CVE-2026-12555?
- Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
- How severe is CVE-2026-12555?
- CVE-2026-12555 has a CVSS 4.0 base score of 7.7, rated high severity.
- Is CVE-2026-12555 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (15th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-12555?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-12555 published?
- CVE-2026-12555 was published on 2026-08-24 and last updated on 2026-09-03.
References
- https://ciphersecuritylabs.com/papers/rooted-in-trust-breaking-hp-easy-starts-macos-privilege-boundaries/
- https://support.hp.com/us-en/document/ish_15512340-15512362-16/hpsbpi04124
Other CWE-379 vulnerabilities
- CVE-2026-85028 — High (CVSS 7.8): Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation…
- CVE-2024-9950 — High (CVSS 7.8): A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify…
- CVE-2024-9500 — High (CVSS 7.8): A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer…
- CVE-2023-6080 — High (CVSS 7.8): Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation…
- CVE-2023-3181 — High (CVSS 7.8): The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at…
- CVE-2023-37243 — High (CVSS 7.8): The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM…