Information Exposure via Misconfigured CORS in HP OfficeJet Pro Printers
CVE-2026-1997

6.9MEDIUM

What is CVE-2026-1997?

Certain HP OfficeJet Pro printers may inadvertently expose sensitive information when Cross-Origin Resource Sharing (CORS) is improperly configured. This misconfiguration could potentially allow unauthorized web origins to gain access to device resources. CORS, which is disabled by default on Pro-class devices, can only be enabled by an administrator through the Embedded Web Server (EWS). It is essential for administrators to keep CORS disabled unless explicitly needed to safeguard against unauthorized interactions and ensure that only trusted solutions access the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HP OfficeJet Pro 7720 Wide Format All-in-One Printer series 0

HP OfficeJet Pro 7730 Wide Format All-in-One Printer 0

HP OfficeJet Pro 7740 Wide Format All-in-One Printer series 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.