Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
Conclusion & alert: CVE-2026-1997 is rated Low Risk (27.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-11 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| hp | m9l65a_firmware | < 001.2602a | cpe:2.3:o:hp:m9l65a_firmware:*:*:*:*:*:*:*:* |
| hp | d9l20a_firmware | < 001.2602b | cpe:2.3:o:hp:d9l20a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s32a_firmware | < 001.2602b | cpe:2.3:o:hp:k7s32a_firmware:*:*:*:*:*:*:*:* |
| hp | d9l21a_firmware | < 001.2602b | cpe:2.3:o:hp:d9l21a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s42a_firmware | < 001.2602b | cpe:2.3:o:hp:k7s42a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g65a_firmware | < 001.2602b | cpe:2.3:o:hp:t0g65a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s39a_firmware | < 001.2602b | cpe:2.3:o:hp:k7s39a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x83a_firmware | < 001.2602b | cpe:2.3:o:hp:j6x83a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s43a_firmware | < 001.2602b | cpe:2.3:o:hp:k7s43a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s40a_firmware | < 001.2602b | cpe:2.3:o:hp:k7s40a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s41a_firmware | < 001.2602b | cpe:2.3:o:hp:k7s41a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g56a_firmware | < 001.2602b | cpe:2.3:o:hp:t0g56a_firmware:*:*:*:*:*:*:*:* |
| hp | d9l63a_firmware | < 001.2602b | cpe:2.3:o:hp:d9l63a_firmware:*:*:*:*:*:*:*:* |
| hp | d9l64a_firmware | < 001.2602b | cpe:2.3:o:hp:d9l64a_firmware:*:*:*:*:*:*:*:* |
| hp | j3p65a_firmware | < 001.2602b | cpe:2.3:o:hp:j3p65a_firmware:*:*:*:*:*:*:*:* |
| hp | j3p66a_firmware | < 001.2602b | cpe:2.3:o:hp:j3p66a_firmware:*:*:*:*:*:*:*:* |
| hp | j3p67a_firmware | < 001.2602b | cpe:2.3:o:hp:j3p67a_firmware:*:*:*:*:*:*:*:* |
| hp | j3p68a_firmware | < 001.2602b | cpe:2.3:o:hp:j3p68a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g70a_firmware | < 001.2602b | cpe:2.3:o:hp:t0g70a_firmware:*:*:*:*:*:*:*:* |
| hp | g5j38a_firmware | < 001.2602a | cpe:2.3:o:hp:g5j38a_firmware:*:*:*:*:*:*:*:* |
| hp | t1p99a_firmware | < 001.2602a | cpe:2.3:o:hp:t1p99a_firmware:*:*:*:*:*:*:*:* |
| hp | l3t99a_firmware | < 001.2602a | cpe:2.3:o:hp:l3t99a_firmware:*:*:*:*:*:*:*:* |
| hp | y0s19a_firmware | < 001.2602a | cpe:2.3:o:hp:y0s19a_firmware:*:*:*:*:*:*:*:* |
| hp | g5j56a_firmware | < 001.2602a | cpe:2.3:o:hp:g5j56a_firmware:*:*:*:*:*:*:*:* |
| hp | y0s18a_firmware | < 001.2602a | cpe:2.3:o:hp:y0s18a_firmware:*:*:*:*:*:*:*:* |
| hp | d9l18a_firmware | < 001.2602a | cpe:2.3:o:hp:d9l18a_firmware:*:*:*:*:*:*:*:* |
| hp | m9l66a_firmware | < 001.2602a | cpe:2.3:o:hp:m9l66a_firmware:*:*:*:*:*:*:*:* |
| hp | m9l67a_firmware | < 001.2602a | cpe:2.3:o:hp:m9l67a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g46a_firmware | < 001.2602a | cpe:2.3:o:hp:t0g46a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x76a_firmware | < 001.2602a | cpe:2.3:o:hp:j6x76a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x78a_firmware | < 001.2602a | cpe:2.3:o:hp:j6x78a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x80a_firmware | < 001.2602a | cpe:2.3:o:hp:j6x80a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s37a_firmware | < 001.2602a | cpe:2.3:o:hp:k7s37a_firmware:*:*:*:*:*:*:*:* |
| hp | m9l70a_firmware | < 001.2602a | cpe:2.3:o:hp:m9l70a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x77a_firmware | < 001.2602a | cpe:2.3:o:hp:j6x77a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x81a_firmware | < 001.2602a | cpe:2.3:o:hp:j6x81a_firmware:*:*:*:*:*:*:*:* |
| hp | j6x79a_firmware | < 001.2602a | cpe:2.3:o:hp:j6x79a_firmware:*:*:*:*:*:*:*:* |
| hp | k7s38a_firmware | < 001.2602a | cpe:2.3:o:hp:k7s38a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g47a_firmware | < 001.2602a | cpe:2.3:o:hp:t0g47a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g48a_firmware | < 001.2602a | cpe:2.3:o:hp:t0g48a_firmware:*:*:*:*:*:*:*:* |
| hp | t0g49a_firmware | < 001.2602a | cpe:2.3:o:hp:t0g49a_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://support.hp.com/us-en/document/ish_14051823-14051849-16/hpsbpi04086 | Vendor Advisory |