CVE-2026-1997: Certain HP OfficeJet Pro Printers - Information Disclosure
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource.
CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1997?
CVE-2026-1997 has a moderate severity level due to the potential information disclosure risk.
How do I fix CVE-2026-1997?
To fix CVE-2026-1997, ensure that Cross-Origin Resource Sharing (CORS) is correctly configured on your HP OfficeJet Pro printer.
Which HP OfficeJet Pro Printers are affected by CVE-2026-1997?
CVE-2026-1997 affects specific HP OfficeJet Pro printers, particularly those with outdated firmware versions prior to 001.2602b.
Can CVE-2026-1997 lead to unauthorized access?
Yes, CVE-2026-1997 can potentially allow unauthorized web origins to access device resources due to misconfigured CORS.
Is CORS enabled by default on affected printers for CVE-2026-1997?
No, CORS is disabled by default on the affected HP OfficeJet Pro class devices.