Description
A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.
Published: 2026-04-23
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Disclosure
Action: Assess Impact
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Canon
Canon i-sensys C1533if Ii
Canon i-sensys Mf842cdw
Canon i-sensys X C1538 If Ii
Canon imageclass X C1538if Ii
Canon imageclass X Mf1538c Ii
Canon imageforce Series
Canon imagepress Series
Canon imagerunner Advance Series
Canon imagerunner Series
Canon mf842cdw
Canon mf842cx
Canon satera Mf7525f
Canon satera Mf7625f
Canon satera Mf7725f
Canon satera Mf842cdw
Vendors & Products Canon
Canon i-sensys C1533if Ii
Canon i-sensys Mf842cdw
Canon i-sensys X C1538 If Ii
Canon imageclass X C1538if Ii
Canon imageclass X Mf1538c Ii
Canon imageforce Series
Canon imagepress Series
Canon imagerunner Advance Series
Canon imagerunner Series
Canon mf842cdw
Canon mf842cx
Canon satera Mf7525f
Canon satera Mf7625f
Canon satera Mf7725f
Canon satera Mf842cdw

Tue, 28 Apr 2026 07:30:00 +0000

Type Values Removed Values Added
Title Browser‑Based Remote Management Interface May Expose Sensitive Device Information in Canon Printers

Fri, 24 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Canon I-sensys C1533if Ii I-sensys Mf842cdw I-sensys X C1538 If Ii Imageclass X C1538if Ii Imageclass X Mf1538c Ii Imageforce Series Imagepress Series Imagerunner Advance Series Imagerunner Series Mf842cdw Mf842cx Satera Mf7525f Satera Mf7625f Satera Mf7725f Satera Mf842cdw
cve-icon MITRE

Status: PUBLISHED

Assigner: Canon

Published:

Updated: 2026-04-24T18:18:56.812Z

Reserved: 2026-02-03T04:38:23.956Z

Link: CVE-2026-1789

cve-icon Vulnrichment

Updated: 2026-04-24T16:50:25.713Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-24T00:16:26.400

Modified: 2026-04-24T14:39:56.310

Link: CVE-2026-1789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T09:25:41Z

Weaknesses