Use of hard-coded cryptographic key in Canon Inc. products - CVE-2026-9260
Published: June 16, 2026
Vulnerability identifier: #VU134585
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9260
CWE-ID: CWE-321
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to use of hard-coded cryptographic key. A local attacker can obtain credentials used for FTP/FTPS/SFTP communication test functions.
Affected software
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
EOS Network Setting Tool for Windows
EOS Utility
How to mitigate CVE-2026-9260
Install updates from vendor's website.
EOS Network Setting Tool for macOS - update to 1.5.1
EOS Network Setting Tool for Windows - update to 1.5.1
EOS Utility - update to 3.20.21
EOS Network Setting Tool for Windows - update to 1.5.1
EOS Utility - update to 3.20.21