Cyber Posture

CVE-2026-2915

HighLPE

Published: 03 March 2026

Published
03 March 2026
Modified
09 March 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score 0.0003 8.1th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-2915 is a high-severity Incorrect Default Permissions (CWE-276) vulnerability in Hp System Event Utility. Its CVSS base score is 7.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 8.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068) and 1 other technique.
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-276 CWE-732

Access control policy can specify and enforce secure default permissions for resources.

addresses: CWE-276 CWE-732

Guides setting of default permissions to the minimum required level.

addresses: CWE-732 CWE-276

Procedures specify correct permission assignments for critical configuration files and resources as part of baseline and change management.

addresses: CWE-276 CWE-732

Baseline establishment and updates on install/upgrade ensure correct default permissions rather than insecure ones.

addresses: CWE-276 CWE-732

Requiring the most restrictive settings instead of defaults prevents incorrect default permissions on resources.

addresses: CWE-732 CWE-276

Places configuration items under formal management, enforcing correct permission assignments on critical resources.

addresses: CWE-732 CWE-276

Policy specifies correct permission assignments for physical critical resources and facilities.

addresses: CWE-276 CWE-732

Tailoring explicitly overrides or scopes default permission assignments in the baseline to match the system's actual risk and operational needs.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
T1485 Data Destruction Impact
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
Why these techniques?

Local arbitrary file write with elevation directly enables T1068 (Exploitation for Privilege Escalation) and facilitates T1485 (Data Destruction) via overwriting critical files to achieve DoS/integrity impact.

Confidence: MEDIUM · MITRE ATT&CK Enterprise v18.1

NVD Description

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

Deeper analysisAI

CVE-2026-2915 is a vulnerability in the HP System Event Utility that might allow denial of service through elevated arbitrary file writes. It affects versions of the HP System Event Utility prior to 3.2.16 and is linked to CWE-276 (Incorrect Default Permissions) and CWE-732 (Incorrect Permission Assignment for Critical Resource). The vulnerability carries a CVSS v3.1 base score of 7.1 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H), indicating high impacts on integrity and availability with no confidentiality impact.

A local attacker with low privileges can exploit this vulnerability with low attack complexity and no user interaction. Exploitation enables elevated arbitrary file writes, potentially leading to denial of service and disruption of system integrity by overwriting critical files.

The HP security bulletin at https://support.hp.com/us-en/document/ish_14271963-14271996-16/hpsbgn04097 addresses this issue, stating that it was remediated in HP System Event Utility version 3.2.16. Security practitioners should update to this version or later to mitigate the risk.

Details

CWE(s)

Affected Products

hp
system event utility
≤ 3.2.16

CVEs Like This One

CVE-2025-11531Same product: Hp System Event Utility
CVE-2025-26506Same vendor: Hp
CVE-2025-26507Same vendor: Hp
CVE-2025-26508Same vendor: Hp
CVE-2025-2268Same vendor: Hp
CVE-2025-24107Shared CWE-276
CVE-2024-53841Shared CWE-276
CVE-2026-21765Shared CWE-276, CWE-732
CVE-2024-53840Shared CWE-276
CVE-2026-2637Shared CWE-732

References