CVE-2026-60011
Last modified
CVE-2026-60011 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Sharp Corporation | Sharp MFPs | see the information provided by Sharp Corporation |
| Toshiba Tec Corporation | Toshiba Tec MFPs | see the information provided by Toshiba Tec |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-60011?
How severe is CVE-2026-60011?
How do I fix CVE-2026-60011?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-60001sshd in OpenSSH before 10.4 does not always honor the minimu…6.5
- CVE-2026-60002ssh in OpenSSH before 10.4 can have a use-after-free when a …9.4
- CVE-2026-60005NGINX Plus and NGINX Open Source have a vulnerability in the…8.2
- CVE-2026-60007In Eclipse Milo versions 0.6.0 through 1.1.4, username-token…7.4
- CVE-2026-60009In Eclipse Theia versions up to and including 1.73.1, the `@…8.8
- CVE-2026-6001Authorization bypass through User-Controlled key vulnerabili…8.8
- CVE-2026-6002Improper neutralization of Script-Related HTML tags in a web…8.8
- CVE-2026-60023Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2026-60024Joomla Extension - joomdonation.com - Insecure default confi…9.8
- CVE-2026-60025Joomla Extension - joomdonation.com - User enumeration in Ev…8.8
- CVE-2026-60026Joomla Extension - themexpert.com - Authenticated PHP code e…8.9
- CVE-2026-60027Joomla Extension - themexpert.com - Unauthenticated path tra…8.7
Are you affected by CVE-2026-60011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
