[Japanese]

JVNDB-2026-026398

Multiple vulnerabilities in Sharp and Toshiba Tec MFPs

Overview

Sharp and Toshiba Tec MFPs (multifunction printers) contain multiple vulnerabilities listed below.
  • User authentication can be bypassed with crafted URLs (CWE-425) - CVE-2026-60011
  • Incomplete cleanup of cached files (CWE-459) - CVE-2026-63545
  • Insecure initial configuration (CWE-1188) - CVE-2026-63563
    • The products for a certain market have been shipped with the user authentication feature disabled in the initial configuration, which means that the address book editing and a range of features related to Document Filing can be accessed without user authentication.
    • Products intended for the Japanese market are not affected by this vulnerability.
CVE-2026-60011 and CVE-2026-63563 were reported directly to Sharp Corporation by the following reporters.
- CVE-2026-60011: Mohamed Abdelhady of Cyber 50 Defense
- CVE-2026-63563: John Jackson

Sharp Corporation reported CVE-2026-63545 to JPCERT/CC.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2026-60011


CVSS v3 Severity
Base Metrics:2.4 (Low) [Other]
  • Access Vector: Physical
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): None
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-63545


CVSS v3 Severity
Base Metrics:6.5 (Medium) [Other]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): Low
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2026-63563
Affected Products


(Multiple Venders)
  • (Multiple Products)

As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed below.
Impact

  • Image data stored to the affected product can be retrieved without authentication (CVE-2026-60011).
  • Some image data are cached internally when printing and left uncleared. They may be accessed later by other users (CVE-2026-63545).
  • If the affected product is used with the initial configuration, any user can access the address book and other resources without authentication (CVE-2026-63563).
Solution

CVE-2026-60011, CVE-2026-63545
[Update the firmware]
Apply the appropriate firmware update according to the information provided by the respective vendors.

CVE-2026-63563
[Apply workaround]
Apply workarounds according to the information provided by the respective vendors.
Vendor Information

Sharp Corporation TOSHIBA TEC
CWE (What is CWE?)

  1. Insecure Default Initialization of Resource(CWE-1188) [Other]
  2. Direct Request ('Forced Browsing')(CWE-425) [Other]
  3. Incomplete Cleanup(CWE-459) [Other]
CVE (What is CVE?)

  1. CVE-2026-60011
  2. CVE-2026-63545
  3. CVE-2026-63563
References

  1. JVN : JVNVU#98759887
Revision History

  • [2026/08/04]
      Web page was published