A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.

Project Subscriptions

Vendors Products
I-sensys C1533if Ii Subscribe
I-sensys Mf842cdw Subscribe
I-sensys X C1538 If Ii Subscribe
Imageclass X C1538if Ii Subscribe
Imageclass X Mf1538c Ii Subscribe
Imageforce Series Subscribe
Imagepress Series Subscribe
Imagerunner Advance Series Subscribe
Imagerunner Series Subscribe
Mf842cdw Subscribe
Mf842cx Subscribe
Satera Mf7525f Subscribe
Satera Mf7625f Subscribe
Satera Mf7725f Subscribe
Satera Mf842cdw Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Canon
Canon i-sensys C1533if Ii
Canon i-sensys Mf842cdw
Canon i-sensys X C1538 If Ii
Canon imageclass X C1538if Ii
Canon imageclass X Mf1538c Ii
Canon imageforce Series
Canon imagepress Series
Canon imagerunner Advance Series
Canon imagerunner Series
Canon mf842cdw
Canon mf842cx
Canon satera Mf7525f
Canon satera Mf7625f
Canon satera Mf7725f
Canon satera Mf842cdw
Vendors & Products Canon
Canon i-sensys C1533if Ii
Canon i-sensys Mf842cdw
Canon i-sensys X C1538 If Ii
Canon imageclass X C1538if Ii
Canon imageclass X Mf1538c Ii
Canon imageforce Series
Canon imagepress Series
Canon imagerunner Advance Series
Canon imagerunner Series
Canon mf842cdw
Canon mf842cx
Canon satera Mf7525f
Canon satera Mf7625f
Canon satera Mf7725f
Canon satera Mf842cdw

Tue, 28 Apr 2026 07:30:00 +0000

Type Values Removed Values Added
Title Browser‑Based Remote Management Interface May Expose Sensitive Device Information in Canon Printers

Fri, 24 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Canon

Published:

Updated: 2026-04-24T18:18:56.812Z

Reserved: 2026-02-03T04:38:23.956Z

Link: CVE-2026-1789

cve-icon Vulnrichment

Updated: 2026-04-24T16:50:25.713Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-24T00:16:26.400

Modified: 2026-04-24T14:39:56.310

Link: CVE-2026-1789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T09:25:41Z

Weaknesses