An HP ThinPro flaw could allow someone with physical access to certain thin clients to bypass disk encryption and recover sensitive local data.

Researchers found the issue in ThinPro 8 and 9, HP’s Linux-based operating system for enterprise thin client devices. The weakness affects how the system validates its boot process before releasing an encryption key.

An attacker would need physical possession of a device and access to its M.2 storage drive. However, the researchers said the attack does not require specialised hardware or advanced reverse engineering.

Startup checks leave a gap

HP ThinPro uses LUKS to encrypt its root partition. The encryption key sits inside the device’s Trusted Platform Module, or TPM, which is designed to protect sensitive cryptographic material.

The TPM checks several early components in the startup chain, including firmware, UEFI drivers and the GRUB bootloader. However, the researchers found that it does not verify every file loaded after that stage.

Some later startup components remain unencrypted. A physical attacker could alter one of these files and cause the system to expose the decryption key during the next boot.

This weakness undermines the purpose of full-disk encryption. Although the TPM protects the key initially, incomplete boot-chain verification can allow a modified startup process to obtain it.

Researchers tested the attack on two devices

The researchers confirmed the HP ThinPro flaw on an HP t530 running ThinPro 8.1.0 build 22 and an HP t540 running ThinPro 9.0.0 build 15.

The attack requires an attacker to remove the M.2 drive, modify data on an unencrypted boot partition and return the drive to the device. After the device starts, the attacker can retrieve the released encryption key and access protected storage.

Thin client systems often rely on remote infrastructure rather than local storage. Even so, they may store Wi-Fi credentials, passwords, configuration profiles and other information that could help an intruder gain access to a wider corporate network.

That makes the issue relevant to organisations that use thin clients in call centres, healthcare facilities, financial services, government environments and other virtual desktop deployments.

HP had not released a fix

The researchers reported the problem to HP on February 22, 2026. HP acknowledged the disclosure and indicated that it intended to address the issue.

However, the 90-day disclosure period passed without a patch. The issue also had no assigned CVE identifier at the time of reporting.

Secure Boot is disabled by default on the affected ThinPro systems. HP’s BIOS settings list it as unsupported for operating systems other than Windows, according to the report.

Security teams can reduce their exposure by setting a BIOS password and enabling Secure Boot where possible. These measures may slow an attacker, but they do not fully resolve the underlying issue.

Conclusion

The HP ThinPro flaw shows why disk encryption must verify the entire startup chain. Organisations should treat vulnerable devices as exposed once they leave physical control and protect or securely destroy their storage during disposal or replacement.


0 responses to “HP ThinPro Flaw Lets Attackers Bypass Disk Encryption”