πŸ›‘οΈ CVE-2026-1997
🟑 CVSS 5.3 β€” Medium βœ… No Known Exploit CWE-346 NVD
5.3
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.

Details

Severity MEDIUM
CVSS Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE CWE-346
Public Exploit βœ… No
Source NVD
Published 2026-02-10
Updated 2026-06-02
Modified 2026-02-12
Fix URL N/A

Affected Packages

Software From version Fixed in
d9l18a-firmware β€” 001.2602a
d9l20a-firmware β€” 001.2602b
d9l21a-firmware β€” 001.2602b
d9l63a-firmware β€” 001.2602b
d9l64a-firmware β€” 001.2602b
g5j38a-firmware β€” 001.2602a
g5j56a-firmware β€” 001.2602a
j3p65a-firmware β€” 001.2602b
j3p66a-firmware β€” 001.2602b
j3p67a-firmware β€” 001.2602b
j3p68a-firmware β€” 001.2602b
j6x76a-firmware β€” 001.2602a
j6x77a-firmware β€” 001.2602a
j6x78a-firmware β€” 001.2602a
j6x79a-firmware β€” 001.2602a
j6x80a-firmware β€” 001.2602a
j6x81a-firmware β€” 001.2602a
j6x83a-firmware β€” 001.2602b
k7s32a-firmware β€” 001.2602b
k7s37a-firmware β€” 001.2602a
k7s38a-firmware β€” 001.2602a
k7s39a-firmware β€” 001.2602b
k7s40a-firmware β€” 001.2602b
k7s41a-firmware β€” 001.2602b
k7s42a-firmware β€” 001.2602b
k7s43a-firmware β€” 001.2602b
l3t99a-firmware β€” 001.2602a
m9l65a-firmware β€” 001.2602a
m9l66a-firmware β€” 001.2602a
m9l67a-firmware β€” 001.2602a
m9l70a-firmware β€” 001.2602a
t0g46a-firmware β€” 001.2602a
t0g47a-firmware β€” 001.2602a
t0g48a-firmware β€” 001.2602a
t0g49a-firmware β€” 001.2602a
t0g56a-firmware β€” 001.2602b
t0g65a-firmware β€” 001.2602b
t0g70a-firmware β€” 001.2602b
t1p99a-firmware β€” 001.2602a
y0s18a-firmware β€” 001.2602a
y0s19a-firmware β€” 001.2602a

Similar Threats

Vulnerability Monitoring

Stay informed about vulnerabilities in your stack

BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts β†’

No credit card required  Β·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.