Improper Certificate Validation in Canon Inc. products - CVE-2026-9258
Published: June 16, 2026
Vulnerability identifier: #VU134583
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-9258
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Canon Inc.
Affected software:
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper validation of SSH host key. A remote attacker can obtain credentials used for FTP/FTPS/SFTP communication test functions.
How to mitigate CVE-2026-9258
Install updates from vendor's website.