CVE-2026-18243
Awaiting Analysis Awaiting Analysis - Queue

Cross-Site Scripting (XSS) in HP DesignJet Printers

Vulnerability report for CVE-2026-18243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: HP Inc.

Description

Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hp designjet *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves cross-site scripting (XSS) in certain HP DesignJet products. It allows unauthenticated HTTP requests to view print job previews, potentially exposing sensitive data or enabling further attacks.

Detection Guidance

Detecting this XSS vulnerability in HP DesignJet products may require checking for unauthenticated HTTP requests to view print job previews. Monitor network traffic for suspicious HTTP requests targeting print job preview endpoints. Inspect web server logs for unusual patterns or requests from unauthorized sources.

Impact Analysis

An attacker could exploit this to access print job previews, which may contain confidential or sensitive information. This could lead to data leaks or unauthorized access to documents.

Compliance Impact

This vulnerability could violate GDPR or HIPAA by exposing personal or health-related data in print job previews. Organizations may face compliance penalties if data breaches occur due to this issue.

Mitigation Strategies

Update HP DesignJet firmware to the latest version provided by HP to address the XSS vulnerability in print job previews.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart