Improper Certificate Validation in Canon Inc. products - CVE-2026-9259
Published: June 16, 2026
Vulnerability identifier: #VU134584
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-9259
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Canon Inc.
Affected software:
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper validation of server certificate. A remote attacker can obtain credentials used for FTP/FTPS/SFTP communication test functions.
How to mitigate CVE-2026-9259
Install updates from vendor's website.