Description
Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.
Published: 2026-09-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary OS command execution for a logged‑in user
Action: Immediate Patch
AI Analysis

Impact

The PFU Image Scanner Driver for Linux contains an OS command injection flaw that allows an authenticated local user to execute arbitrary commands on the host. This vulnerability can lead to complete compromise of confidentiality, integrity, and availability of the affected system, as the attacker could run any shell command with the privileges of the user who logged in.

Affected Systems

The vulnerability affects PFU Limited Image Scanner Driver for Linux, specifically the SP Series and fi Series drivers. No specific version numbers are provided in the available data, so all deployments of these drivers are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires the attacker to be authenticated on the Linux system, which suggests that the exploitation vector is a local attacker with login capability. While the risk is moderate, any user with access to the affected driver could potentially elevate privileges or compromise the system if the vulnerability is actively exploited.

Generated by OpenCVE AI on September 30, 2026 at 07:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official firmware or driver update released by PFU Limited that fixes the command injection flaw.
  • Restrict use of the image scanner driver to privileged users only and enforce strict user access controls.
  • If a firmware or driver upgrade is not yet available, uninstall or disable the driver to eliminate the attack surface until the patch is released.

Generated by OpenCVE AI on September 30, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in PFU Image Scanner Driver for Linux

Wed, 30 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T15:28:12.170Z

Reserved: 2026-09-04T00:52:00.615Z

Link: CVE-2026-78229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T02:16:57.583

Modified: 2026-09-30T16:47:57.730

Link: CVE-2026-78229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')