Incomplete cleanup in Toshiba products - CVE-2026-63545

 

Incomplete cleanup in Toshiba products - CVE-2026-63545

Published: August 3, 2026


Vulnerability identifier: #VU140745
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63545
CWE-ID: CWE-459
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to some image data are cached internally when printing and left uncleared. An attacker with physical access can gain access to sensitive information on the target system.


Affected software

e-STUDIO 908
e-STUDIO 1058
e-STUDIO 1208
e-STUDIO 907
e-STUDIO 1057
e-STUDIO 1207

How to mitigate CVE-2026-63545

Install updates from vendor's website.


External References

Related Security Bulletins