CVE-2026-18243 Details
Description
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.
A cross-site scripting (XSS) vulnerability has been identified in certain HP DesignJet products, including the HP DesignJet T3500. This vulnerability may allow unauthenticated HTTP requests to access print job previews. The issue arises from improper handling of user input, which could be exploited to inject malicious scripts.
Users are advised to update their printer firmware to the latest version. Firmware updates for potentially affected products can be obtained through the HP Software and Driver Downloads website by searching for the specific printer model.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |