CVE-2026-1997: Certain HP OfficeJet Pro Printers - Information Disclosure

Published Feb 10, 2026
·
Updated

Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource.

CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.

Affected Software

83 affected components
HP OfficeJet Pro Printers
All of the following
HP M9l65a Firmware<001.2602a
HP M9l65a
All of the following
HP D9l20a Firmware<001.2602b
HP D9l20a
All of the following
HP K7s32a Firmware<001.2602b
HP K7s32a
All of the following
HP D9l21a Firmware<001.2602b
HP D9l21a
All of the following
HP K7s42a Firmware<001.2602b
HP K7s42a
All of the following
HP T0g65a Firmware<001.2602b
HP T0g65a
All of the following
HP K7s39a Firmware<001.2602b
HP K7s39a
All of the following
HP J6x83a Firmware<001.2602b
HP J6x83a
All of the following
HP K7s43a Firmware<001.2602b
HP K7s43a
All of the following
HP K7s40a Firmware<001.2602b
HP K7s40a
All of the following
HP K7s41a Firmware<001.2602b
HP K7s41a
All of the following
HP T0g56a Firmware<001.2602b
HP T0g56a
All of the following
HP D9l63a Firmware<001.2602b
HP D9l63a
All of the following
HP D9l64a Firmware<001.2602b
HP D9l64a
All of the following
HP J3p65a Firmware<001.2602b
HP J3p65a
All of the following
HP J3p66a Firmware<001.2602b
HP J3p66a
All of the following
HP J3p67a Firmware<001.2602b
HP J3p67a
All of the following
HP J3p68a Firmware<001.2602b
HP J3p68a
All of the following
HP T0g70a Firmware<001.2602b
HP T0g70a
All of the following
HP G5j38a Firmware<001.2602a
HP G5j38a
All of the following
HP T1p99a Firmware<001.2602a
HP T1p99a
All of the following
HP L3t99a Firmware<001.2602a
HP L3t99a
All of the following
HP Y0s19a Firmware<001.2602a
HP Y0s19a
All of the following
HP G5j56a Firmware<001.2602a
HP G5j56a
All of the following
HP Y0s18a Firmware<001.2602a
HP Y0s18a
All of the following
HP D9l18a Firmware<001.2602a
HP D9l18a
All of the following
HP M9l66a Firmware<001.2602a
HP M9l66a
All of the following
HP M9l67a Firmware<001.2602a
HP M9l67a
All of the following
HP T0g46a Firmware<001.2602a
HP T0g46a
All of the following
HP J6x76a Firmware<001.2602a
HP J6x76a
All of the following
HP J6x78a Firmware<001.2602a
HP J6x78a
All of the following
HP J6x80a Firmware<001.2602a
HP J6x80a
All of the following
HP K7s37a Firmware<001.2602a
HP K7s37a
All of the following
HP M9l70a Firmware<001.2602a
HP M9l70a
All of the following
HP J6x77a Firmware<001.2602a
HP J6x77a
All of the following
HP J6x81a Firmware<001.2602a
HP J6x81a
All of the following
HP J6x79a Firmware<001.2602a
HP J6x79a
All of the following
HP K7s38a Firmware<001.2602a
HP K7s38a
All of the following
HP T0g47a Firmware<001.2602a
HP T0g47a
All of the following
HP T0g48a Firmware<001.2602a
HP T0g48a
All of the following
HP T0g49a Firmware<001.2602a
HP T0g49a

Event History

Feb 10, 2026
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-1997?

CVE-2026-1997 has a moderate severity level due to the potential information disclosure risk.

2

How do I fix CVE-2026-1997?

To fix CVE-2026-1997, ensure that Cross-Origin Resource Sharing (CORS) is correctly configured on your HP OfficeJet Pro printer.

3

Which HP OfficeJet Pro Printers are affected by CVE-2026-1997?

CVE-2026-1997 affects specific HP OfficeJet Pro printers, particularly those with outdated firmware versions prior to 001.2602b.

4

Can CVE-2026-1997 lead to unauthorized access?

Yes, CVE-2026-1997 can potentially allow unauthorized web origins to access device resources due to misconfigured CORS.

5

Is CORS enabled by default on affected printers for CVE-2026-1997?

No, CORS is disabled by default on the affected HP OfficeJet Pro class devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203