Description
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
Published: 2026-08-02
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insecure deserialization flaw in Canon PRISMAproduction that allows an attacker to execute arbitrary code. It is identified as CWE-502. A malicious actor can send crafted serialized data to the application and trigger code execution, potentially compromising the device and the wider network.

Affected Systems

Users running Canon PRISMAproduction version 6.5 or earlier are affected. The issue has been reported for all builds up to and including version 6.5; newer versions are presumed to be unaffected unless otherwise noted by Canon.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity, but the EPSS score is not available, so the exploitation likelihood is unclear. The vulnerability is not yet listed in CISA's KEV catalog, suggesting no widespread exploitation has been reported. Attackers would likely deliver the payload over the network by exploiting the deserialization processing, so systems exposed to untrusted input should be considered high risk until a patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released patches or upgrade to a version newer than 6.5.
  • Restrict network exposure to the PRISMAproduction device by placing it behind a firewall and blocking unsolicited connections that could carry malicious serialized data.
  • Disable or limit functionality that accepts serialized object input if it is not needed for operational purposes.
  • Continue to monitor the device logs for signs of deserialization attacks and review access controls regularly.

Generated by OpenCVE AI on August 3, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Canon Production Printing
Canon Production Printing prismaproduction
Vendors & Products Canon Production Printing
Canon Production Printing prismaproduction

Mon, 03 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability in Canon PRISMAproduction Allowing Arbitrary Code Execution

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Canon Production Printing Prismaproduction
cve-icon MITRE

Status: PUBLISHED

Assigner: Canon

Published:

Updated: 2026-08-03T14:53:56.630Z

Reserved: 2026-02-26T03:05:37.838Z

Link: CVE-2026-3245

cve-icon Vulnrichment

Updated: 2026-08-03T14:53:52.284Z

cve-icon NVD

Status : Received

Published: 2026-08-03T00:16:29.280

Modified: 2026-08-03T16:16:29.437

Link: CVE-2026-3245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:52:49Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data