CVE-2026-5922: HP Inc Poly Ccx
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.
Affected products
- HP Inc Poly Ccx: before 9.5.0 (fixed in 9.5.0)
- HP Inc Poly Edge E: before 8.6.0 (fixed in 8.6.0)
- HP Inc Poly Trio c60: before 9.5.0 (fixed in 9.5.0)
Published 2026-07-08. Last modified 2026-07-09.