CVE-2026-1997
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource.
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- hp/m9l65a firmware · hp/d9l20a firmware · hp/k7s32a firmware · hp/d9l21a firmware · hp/k7s42a firmware · hp/t0g65a firmware · hp/k7s39a firmware · hp/j6x83a firmware · hp/k7s43a firmware · hp/k7s40a firmware · hp/k7s41a firmware · hp/t0g56a firmware · hp/d9l63a firmware · hp/d9l64a firmware · hp/j3p65a firmware · hp/j3p66a firmware · hp/j3p67a firmware · hp/j3p68a firmware · hp/t0g70a firmware · hp/g5j38a firmware · +21 more
- Source
- hp-security-alert@hp.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.