CVE-2026-1789Disclosure

LOWCVSS 6.9 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain production printers and office/small office multifunction printers.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-807

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-28)
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-25: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-28: 2PoC Mentioned / Linked · 2026-05-28: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-28: 204-2505-1205-1305-28
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-251
Disclosure1
2026-05-121
Disclosure1
2026-05-131
General1
2026-05-282
Disclosure2
Full discourse5 posts
  • Praetorian@praetorianlabs
    Disclosure

    🖨️ Default-cred Canon printer to full domain compromise. Config export "encryption" is client-side. Flip the param, server returns the file in plaintext. CVE-2026-1789, 200+ models. https://www.praetorian.com/blog/canon-printer-credential-leak/ #OffensiveSecurity #Praetorian #PraetorianGuard

    Post summary

    The post announces CVE-2026-1789, detailing how a client‑side configuration export flaw can leak plaintext credentials to fully compromise a domain, with a link to a Praetorian blog for further information.

    170114857
    8.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-1789 in 200+ Canon imageRUNNER models allows plaintext credential extraction via client-side encryption bypass. Researchers achieved full domain compromise from printer with default creds. #DFIR_Radar https://t.co/gk85jXBV9l

    Post summary

    Researchers discovered CVE‑2026‑1789 in Canon imageRUNNER printers, enabling plaintext credential extraction and full domain compromise via client-side encryption bypass. The post details the vulnerability’s technical aspects but offers no PoC, exploit code, or patch information.

    10010163
    1.5K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    General

    https://security.splash-eng.com/higashiyama-qilin-ransomware-leak-2026/ https://security.splash-eng.com/kura-sushi-app-cve-2026-41872/ https://security.splash-eng.com/canon-multifunction-cve-2026-1789/ https://security.splash-eng.com/shinnihon-kentei-ransomware-2026/

    Post summary

    The URLs reference several 2026 CVEs and ransomware incidents, but no explicit details, PoCs, exploits, or patches are provided in the text.

    0002061
    1.2K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【JVNVU#90878203: キヤノン製プロダクションプリンター、オフィス/スモールオフィス向け複合機における機微な情報を取得可能な脆弱性】 JVNは、キヤノン製プロダクションプリンターおよびオフィス/スモールオフィス向け複合機に、機微な情報を取得可能な脆弱性 CVE-2026-1789 が存在すると公表しました。管理者権限でログイン可能な攻撃者が細工したリクエストを送信した場合、製品内部の機微な情報を取得される可能性があります。 複合機は単なる印刷機ではなく、アドレス帳、スキャン送信先、部門ID、認証情報、文書処理履歴に近い情報を扱う業務機器です。ネットワーク上で管理画面へ到達可能な構成の場合、内部情報の取得や後続のなりすましに悪用される可能性があります。 防御側は、対象機種とファームウェアを確認し、最新版へ更新してください。あわせて、複合機をファイアウォール内やプライベートIPで利用し、管理画面へのアクセス制限、管理者パスワード変更、アドレス帳・スキャン送信設定の確認を行うべきです。 #キヤノン #複合機セキュリティ #JVN #CVE20261789 #プリンター #ファームウェア更新 https://jvn.jp/vu/JVNVU90878203/index.html

    Post summary

    The post announces a new CVE (CVE-2026-1789) affecting Canon production printers and small‑office multifunction devices, details the sensitive data that could be accessed, and recommends firmware updates and network restrictions as a mitigation.

    00000248
    3.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1789 A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affectin… https://www.cve.org/CVERecord?id=CVE-2026-1789

    Post summary

    The tweet announces CVE-2026-1789 as a vulnerability in a browser-based remote management interface that could let administrators access sensitive device information via crafted requests, with a link to the CVE record.

    0000084
    57.2K followersView on X

Explore more