Certain HP OfficeJet Pro Printers - Information Disclosure
Published Feb 10, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.21%
Description
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource.
CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS). Keeping CORS disabled unless explicitly required helps ensure that only trusted solutions can interact with the device.
Affected products
- Vendor HP Inc Product HP OfficeJet Pro 7720 Wide Format All-in-One Printer series Defaultunaffected
- Version 0StatusaffectedConstraints<<002.2602A
- Version
-
- Version 0StatusaffectedConstraints<<002.2602A
- Version
- Vendor HP Inc Product HP OfficeJet Pro 7740 Wide Format All-in-One Printer series Defaultunaffected
- Version 0StatusaffectedConstraints<<002.2602A
- Version
-
- Version 0StatusaffectedConstraints<<001.2602B
- Version
-
- Version 0StatusaffectedConstraints<<001.2602A
- Version
-
- Version 0StatusaffectedConstraints<<001.2602B
- Version
-
- Version 0StatusaffectedConstraints<<001.2602B
- Version
-
- Version 0StatusaffectedConstraints<<001.2602B
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HP Inc | HP OfficeJet Pro 7720 Wide Format All-in-One Printer series | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 7730 Wide Format All-in-One Printer | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 7740 Wide Format All-in-One Printer series | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 8210 Printer series | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 8710 All-in-One Printer series | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 8730 All-in-One Printer | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 8730 Mono Printer series | unaffected |
| ||||||
| HP Inc | HP OfficeJet Pro 8740 All-in-One Printer series | unaffected |
|
Configuration 1
- < 001.2602a
Configuration 2
- < 001.2602b
Configuration 3
- < 001.2602b
Configuration 4
- < 001.2602b
Configuration 5
- < 001.2602b
Configuration 6
- < 001.2602b
Configuration 7
- < 001.2602b
Configuration 8
- < 001.2602b
Configuration 9
- < 001.2602b
Configuration 10
- < 001.2602b
Configuration 11
- < 001.2602b
Configuration 12
- < 001.2602b
Configuration 13
- < 001.2602b
Configuration 14
- < 001.2602b
Configuration 15
- < 001.2602b
Configuration 16
- < 001.2602b
Configuration 17
- < 001.2602b
Configuration 18
- < 001.2602b
Configuration 19
- < 001.2602b
Configuration 20
- < 001.2602a
Configuration 21
- < 001.2602a
Configuration 22
- < 001.2602a
Configuration 23
- < 001.2602a
Configuration 24
- < 001.2602a
Configuration 25
- < 001.2602a
Configuration 26
- < 001.2602a
Configuration 27
- < 001.2602a
Configuration 28
- < 001.2602a
Configuration 29
- < 001.2602a
Configuration 30
- < 001.2602a
Configuration 31
- < 001.2602a
Configuration 32
- < 001.2602a
Configuration 33
- < 001.2602a
Configuration 34
- < 001.2602a
Configuration 35
- < 001.2602a
Configuration 36
- < 001.2602a
Configuration 37
- < 001.2602a
Configuration 38
- < 001.2602a
Configuration 39
- < 001.2602a
Configuration 40
- < 001.2602a
Configuration 41
- < 001.2602a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Feb 10, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.21% (0.00210) | 10.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.20% (0.00198) | 9.66th | v5 (v2026.06.15) |
| Feb 11, 2026 | 0.01% (0.00006) | 0.36th | v4 (v2025.03.14) |
References (1)
| Link | Providers | Tags |
|---|---|---|
| https://support.hp.com/us-en/document/ish_14051823-14051849-16/hpsbpi04086 | Vendor Advisory |
Change history (0)
No recorded changes yet.