CVE-2026-1789

MEDIUMCVSS 6.9/10EPSS 0.29%

Last modified

CVE-2026-1789 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.

Description

A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.

Metrics

CVSS 3.1
4.9/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVSS 4.0
6.9/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.29%

21.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Canon Inc.imagePRESS Seriesall version
Canon Inc.imageFORCE Seriesall version
Canon Inc.imageRUNNER ADVANCE Seriesall version
Canon Inc.imageRUNNER Seriesall version
Canon Inc.Satera MF7525Fv15.00 or earlier
Canon Inc.Satera MF7625Fv8.12 or earlier
Canon Inc.Satera MF7725Fv16.04 or earlier
Canon Inc.Satera MF842CDWv16.04 or earlier
Canon Inc.imageCLASS X C1538iF IIv16.04 or earlier
Canon Inc.imageCLASS X MF1538C IIv16.04 or earlier
Canon Inc.i-SENSYS C1533iF IIv16.04 or earlier
Canon Inc.i-SENSYS X C1538 iF IIv16.04 or earlier
Canon Inc.i-SENSYS MF842Cdwv16.04 or earlier
Canon Inc.MF842CDWv16.04 or earlier
Canon Inc.MF842CXv16.04 or earlier

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-1789?
A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.
How severe is CVE-2026-1789?
CVE-2026-1789 has a CVSS score of 6.9/10 (MEDIUM severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2026-1789?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-1789?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST