← Vulnerability feed

Vulnerability record · CVE-2026-1997 · published 10 February 2026

CVE-2026-1997: Hp m9l65a firmware origin validation error vulnerability

Hp · M9l65a Firmware

Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.

6.9 CVSS 4.0 Medium EPSS 0.22% · top 88.1% CWE-346 · Origin validation error
6.9CVSS 4.0 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
41Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

41 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1997 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28722Hp p4c78a firmware classic buffer overflow vulnerabilityCertain HP Print Products are potentially vulnerable to Buffer Overflow.EPSS 1.3%9.8CVE-2019-10627Qualcomm ips memory buffer overflow vulnerabilityInteger overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to in…EPSS 1.4%9.8CVE-2017-2741HP PageWide and OfficeJet Pro printers allow remote code executionHP PageWide and OfficeJet Pro printers running firmware before 1708D contain a vulnerability that can be exploited to execute arbitrary code. The rec…EPSS 85%analysed6.9CVE-2026-1996Hp d9l18a firmware vulnerabilityCertain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP c…EPSS 0.31%5.2CVE-2019-6337Hp d9l63a firmware vulnerabilityFor the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer p…EPSS 0.42%9.4CVE-2025-34291Langflow CORS misconfiguration leads to token theft and RCELangflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token …KEVEPSS 93%analysed8.8CVE-2015-4495Firefox PDF reader same-origin bypass allows file read and privilege gainThe PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, l…KEVEPSS 69%analysed

Source: NIST National Vulnerability Database (record CVE-2026-1997), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.