CVE-2026-1578
Medium
|5.1Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into the HP App for Android, potentially compromising user data or hijacking sessions. It mainly affects users who are running outdated versions of the app on their mobile devices, so updating to the latest version is crucial for protection.
Technical Description
HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
CVSS Vector Analysis
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged
Vector String
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$690($500-$1K)
Vendor Response
Grade APatched in 0 days
Quick Information
Published
Feb 13, 2026
7 days ago
Last Modified
Feb 13, 2026
7 days ago