Description
Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
Published: 2026-08-03
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Sharp and Toshiba Tec multifunction printers permits an attacker to directly retrieve image data stored on the device without proper authorization. This flaw undermines the confidentiality of user‑generated documents, allowing a potential attacker to read or download private images that were captured or scanned. The weakness is a classic authorization issue, corresponding to CWE-425, which states that a system fails to enforce proper access control on a resource.

Affected Systems

Sharp Corporation’s Sharp MFP line and Toshiba Tec Corporation’s Toshiba Tec MFP line are affected. The advisory does not list specific firmware or hardware revisions, so it is presumed that all current models supporting image retrieval are vulnerable.

Risk and Exploitability

The CVSS score of 6.9 places the flaw in the medium severity range, and the lack of a public exploit or listing in the KEV catalog suggests that active exploitation is limited at present. However, the vulnerability can be triggered by any user with network or local access to the printer’s control interface, so attackers could potentially retrieve photos or scans by sending specially crafted requests. Because the EPSS score is not available, the exact probability of exploitation remains uncertain, but the medium CVSS score and the nature of the flaw warrant prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided firmware update that fixes the image data authorization issue.
  • Disable the image export feature via the printer’s configuration if it is not needed.
  • Restrict access to the printer’s management interface to trusted local networks using firewall or network segmentation.

Generated by OpenCVE AI on August 4, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sharp Corporation
Sharp Corporation sharp Mfps
Toshiba Tec Corporation
Toshiba Tec Corporation toshiba Tec Mfps
Vendors & Products Sharp Corporation
Sharp Corporation sharp Mfps
Toshiba Tec Corporation
Toshiba Tec Corporation toshiba Tec Mfps

Tue, 04 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Direct Access to Image Data in Sharp and Toshiba Tec MFPs

Mon, 03 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Sharp Corporation Sharp Mfps
Toshiba Tec Corporation Toshiba Tec Mfps
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-03T11:16:54.126Z

Reserved: 2026-07-21T08:39:03.927Z

Link: CVE-2026-60011

cve-icon Vulnrichment

Updated: 2026-08-03T11:16:47.145Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-03T09:17:05.767

Modified: 2026-08-03T17:40:27.300

Link: CVE-2026-60011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:22:21Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')