CVE-2026-4682: Certain HP DeskJet All In One (AIO) Devices – Potential Remote Code Execution & Potential Buffer Overflow
Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP.
WSD Scan is a Microsoft Windows–based network scanning protocol that allows a PC to discover scanners (and MFPs) on a network and send scan jobs to them without requiring vendor specific drivers or utilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4682?
CVE-2026-4682 is considered high severity due to its potential for remote code execution.
How do I fix CVE-2026-4682?
To fix CVE-2026-4682, ensure that your HP DeskJet All-in-One devices are updated with the latest firmware provided by HP.
Which HP devices are affected by CVE-2026-4682?
CVE-2026-4682 affects certain HP DeskJet All-in-One devices that support Web Services for Devices (WSD).
What type of vulnerability is CVE-2026-4682?
CVE-2026-4682 is a potential remote code execution vulnerability that may result from a buffer overflow.
How can I determine if my HP DeskJet device is vulnerable to CVE-2026-4682?
You can determine if your device is vulnerable by checking for specific model information and comparing it with the affected software list provided by HP.