SB2026080323 - Multiple vulnerabilities in Toshiba Tec MFPs
Published: August 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Direct Request ('Forced Browsing') (CVE-ID: CVE-2026-60011)
CWE-ID: CWE-425 - Direct Request ('Forced Browsing')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to forced browsing issue. A remote attacker can retrieve image data stored to the affected product without authentication.
2) Incomplete cleanup (CVE-ID: CVE-2026-63545)
CWE-ID: CWE-459 - Incomplete cleanup
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to some image data are cached internally when printing and left uncleared. An attacker with physical access can gain access to sensitive information on the target system.
3) Insecure Default Initialization of Resource (CVE-ID: CVE-2026-63563)
CWE-ID: CWE-1188 - Insecure Default Initialization of Resource
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromsie the target system.
The vulnerability exists due to insecure default initialization of resource. A remote attacker can access the address book and other resources without authentication.
Remediation
Install update from vendor's website.