SB2026080323 - Multiple vulnerabilities in Toshiba Tec MFPs



SB2026080323 - Multiple vulnerabilities in Toshiba Tec MFPs

Published: August 3, 2026

Security Bulletin ID SB2026080323
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Direct Request ('Forced Browsing') (CVE-ID: CVE-2026-60011)

CWE-ID: CWE-425 - Direct Request ('Forced Browsing')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to forced browsing issue. A remote attacker can retrieve image data stored to the affected product without authentication.


2) Incomplete cleanup (CVE-ID: CVE-2026-63545)

CWE-ID: CWE-459 - Incomplete cleanup

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to some image data are cached internally when printing and left uncleared. An attacker with physical access can gain access to sensitive information on the target system.


3) Insecure Default Initialization of Resource (CVE-ID: CVE-2026-63563)

CWE-ID: CWE-1188 - Insecure Default Initialization of Resource

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromsie the target system.

The vulnerability exists due to insecure default initialization of resource. A remote attacker can access the address book and other resources without authentication.


Remediation

Install update from vendor's website.