Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 18 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Authorization Allows Retrieval of User Registration Information and OIDC Tokens via Man‑in‑the‑Middle |
Fri, 09 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ricoh
Ricoh streamline Nx |
|
| Vendors & Products |
Ricoh
Ricoh streamline Nx |
Fri, 09 Jan 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved. | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-01-09T18:11:55.373Z
Reserved: 2025-12-24T07:24:57.904Z
Link: CVE-2026-21409
Updated: 2026-01-09T18:11:50.599Z
Status : Deferred
Published: 2026-01-09T08:15:58.297
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-21409
No data.
OpenCVE Enrichment
Updated: 2026-04-18T07:30:36Z