Information Exposure via Misconfigured CORS in HP OfficeJet Pro Printers
CVE-2026-1997
What is CVE-2026-1997?
Certain HP OfficeJet Pro printers may inadvertently expose sensitive information when Cross-Origin Resource Sharing (CORS) is improperly configured. This misconfiguration could potentially allow unauthorized web origins to gain access to device resources. CORS, which is disabled by default on Pro-class devices, can only be enabled by an administrator through the Embedded Web Server (EWS). It is essential for administrators to keep CORS disabled unless explicitly needed to safeguard against unauthorized interactions and ensure that only trusted solutions access the device.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HP OfficeJet Pro 7720 Wide Format All-in-One Printer series 0
HP OfficeJet Pro 7730 Wide Format All-in-One Printer 0
HP OfficeJet Pro 7740 Wide Format All-in-One Printer series 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
