CVE-2026-5922: HP Inc Poly Ccx

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.

Affected products

  • HP Inc Poly Ccx: before 9.5.0 (fixed in 9.5.0)
  • HP Inc Poly Edge E: before 8.6.0 (fixed in 8.6.0)
  • HP Inc Poly Trio c60: before 9.5.0 (fixed in 9.5.0)

Published 2026-07-08. Last modified 2026-07-09.