CVE-2026-1997
Last modified
CVE-2026-1997 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | M9l65a Firmware | < 001.2602a |
| Hp | D9l20a Firmware | < 001.2602b |
| Hp | K7s32a Firmware | < 001.2602b |
| Hp | D9l21a Firmware | < 001.2602b |
| Hp | K7s42a Firmware | < 001.2602b |
| Hp | T0g65a Firmware | < 001.2602b |
| Hp | K7s39a Firmware | < 001.2602b |
| Hp | J6x83a Firmware | < 001.2602b |
| Hp | K7s43a Firmware | < 001.2602b |
| Hp | K7s40a Firmware | < 001.2602b |
| Hp | K7s41a Firmware | < 001.2602b |
| Hp | T0g56a Firmware | < 001.2602b |
| Hp | D9l63a Firmware | < 001.2602b |
| Hp | D9l64a Firmware | < 001.2602b |
| Hp | J3p65a Firmware | < 001.2602b |
| Hp | J3p66a Firmware | < 001.2602b |
| Hp | J3p67a Firmware | < 001.2602b |
| Hp | J3p68a Firmware | < 001.2602b |
| Hp | T0g70a Firmware | < 001.2602b |
| Hp | G5j38a Firmware | < 001.2602a |
| Hp | T1p99a Firmware | < 001.2602a |
| Hp | L3t99a Firmware | < 001.2602a |
| Hp | Y0s19a Firmware | < 001.2602a |
| Hp | G5j56a Firmware | < 001.2602a |
| Hp | Y0s18a Firmware | < 001.2602a |
| Hp | D9l18a Firmware | < 001.2602a |
| Hp | M9l66a Firmware | < 001.2602a |
| Hp | M9l67a Firmware | < 001.2602a |
| Hp | T0g46a Firmware | < 001.2602a |
| Hp | J6x76a Firmware | < 001.2602a |
| Hp | J6x78a Firmware | < 001.2602a |
| Hp | J6x80a Firmware | < 001.2602a |
| Hp | K7s37a Firmware | < 001.2602a |
| Hp | M9l70a Firmware | < 001.2602a |
| Hp | J6x77a Firmware | < 001.2602a |
| Hp | J6x81a Firmware | < 001.2602a |
| Hp | J6x79a Firmware | < 001.2602a |
| Hp | K7s38a Firmware | < 001.2602a |
| Hp | T0g47a Firmware | < 001.2602a |
| Hp | T0g48a Firmware | < 001.2602a |
| Hp | T0g49a Firmware | < 001.2602a |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-1997?
How severe is CVE-2026-1997?
How do I fix CVE-2026-1997?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1991A vulnerability was detected in libuvc up to 0.0.7. Affected…5.5
- CVE-2026-1992The ExactMetrics – Google Analytics Dashboard for WordPress …8.8
- CVE-2026-1993The ExactMetrics – Google Analytics Dashboard for WordPress …8.8
- CVE-2026-1994The s2Member plugin for WordPress is vulnerable to privilege…9.8
- CVE-2026-1995In versions before 7.0.0.64, IDrive’s id_service.exe process…7.8
- CVE-2026-1996Certain HP OfficeJet Pro printers may be vulnerable to poten…5.3
- CVE-2026-1998A flaw has been found in micropython up to 1.27.0. This vuln…5.5
- CVE-2026-1999An incorrect authorization vulnerability was identified in G…6.5
- CVE-2026-2000A vulnerability was found in DCN DCME-320 up to 20260121. Im…7.2
- CVE-2026-20001A vulnerability in the REST API of Cisco Secure FMC Software…6.5
- CVE-2026-20002A vulnerability in the web-based management interface of Cis…8.1
- CVE-2026-20003A vulnerability in the REST API of Cisco Secure FMC Software…4.9
Are you affected by CVE-2026-1997?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
