Use of hard-coded cryptographic key in Canon Inc. products - CVE-2026-9260
Published: June 16, 2026
Vulnerability identifier: #VU134585
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-9260
CWE-ID: CWE-321
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Canon Inc.
Affected software:
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
Detailed vulnerability description
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to use of hard-coded cryptographic key. A local attacker can obtain credentials used for FTP/FTPS/SFTP communication test functions.
How to mitigate CVE-2026-9260
Install updates from vendor's website.