CVE-2026-1997

MEDIUM EPSS 9.8%
Published Feb 10, 20264mo ago · Modified Feb 12, 20264mo ago
6.9 CVSS 4.0
Medium
Find Similar
Published Feb 10, 2026 4mo ago
Last Modified Feb 12, 2026 4mo ago

Description

Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.

CVSS Details

Base Score
6.9
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
9.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-346

Affected Products 82

VendorProductVersionRange
hpm9l65a_firmware* <001.2602a
hpm9l65a*any
hpd9l20a_firmware* <001.2602b
hpd9l20a*any
hpk7s32a_firmware* <001.2602b
hpk7s32a*any
hpd9l21a_firmware* <001.2602b
hpd9l21a*any
hpk7s42a_firmware* <001.2602b
hpk7s42a*any
hpt0g65a_firmware* <001.2602b
hpt0g65a*any
hpk7s39a_firmware* <001.2602b
hpk7s39a*any
hpj6x83a_firmware* <001.2602b
hpj6x83a*any
hpk7s43a_firmware* <001.2602b
hpk7s43a*any
hpk7s40a_firmware* <001.2602b
hpk7s40a*any
hpk7s41a_firmware* <001.2602b
hpk7s41a*any
hpt0g56a_firmware* <001.2602b
hpt0g56a*any
hpd9l63a_firmware* <001.2602b
hpd9l63a*any
hpd9l64a_firmware* <001.2602b
hpd9l64a*any
hpj3p65a_firmware* <001.2602b
hpj3p65a*any
hpj3p66a_firmware* <001.2602b
hpj3p66a*any
hpj3p67a_firmware* <001.2602b
hpj3p67a*any
hpj3p68a_firmware* <001.2602b
hpj3p68a*any
hpt0g70a_firmware* <001.2602b
hpt0g70a*any
hpg5j38a_firmware* <001.2602a
hpg5j38a*any
hpt1p99a_firmware* <001.2602a
hpt1p99a*any
hpl3t99a_firmware* <001.2602a
hpl3t99a*any
hpy0s19a_firmware* <001.2602a
hpy0s19a*any
hpg5j56a_firmware* <001.2602a
hpg5j56a*any
hpy0s18a_firmware* <001.2602a
hpy0s18a*any
hpd9l18a_firmware* <001.2602a
hpd9l18a*any
hpm9l66a_firmware* <001.2602a
hpm9l66a*any
hpm9l67a_firmware* <001.2602a
hpm9l67a*any
hpt0g46a_firmware* <001.2602a
hpt0g46a*any
hpj6x76a_firmware* <001.2602a
hpj6x76a*any
hpj6x78a_firmware* <001.2602a
hpj6x78a*any
hpj6x80a_firmware* <001.2602a
hpj6x80a*any
hpk7s37a_firmware* <001.2602a
hpk7s37a*any
hpm9l70a_firmware* <001.2602a
hpm9l70a*any
hpj6x77a_firmware* <001.2602a
hpj6x77a*any
hpj6x81a_firmware* <001.2602a
hpj6x81a*any
hpj6x79a_firmware* <001.2602a
hpj6x79a*any
hpk7s38a_firmware* <001.2602a
hpk7s38a*any
hpt0g47a_firmware* <001.2602a
hpt0g47a*any
hpt0g48a_firmware* <001.2602a
hpt0g48a*any
hpt0g49a_firmware* <001.2602a
hpt0g49a*any

References 1

  • support.hp.com https://support.hp.com/us-en/document/ish_14051823-14051849-16/hpsbpi04086
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.