Insecure Default Initialization of Resource in Canon Inc. products - CVE-2026-9262
Published: June 16, 2026
Vulnerability identifier: #VU134595
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-9262
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Canon Inc.
Affected software:
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to default FTP connection settings use an insecure protocol. A remote attacker can obtain credentials used for FTP/FTPS/SFTP communication test functions.
How to mitigate CVE-2026-9262
Install updates from vendor's website.