[Japanese]

JVNDB-2026-036180

Path traversal vulnerability in FUJIFILM Business Innovation and Sharp MFPs (multifunction printers)

Overview

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Sharp Corporation contain a path traversal vulnerability.
  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) - CVE-2026-78249
FUJIFILM Business Innovation Corp. reported this vulnerability to JPCERT/CC to notify users of the solution through JVN. JPCERT/CC coordinated with FUJIFILM Business Innovation Corp. and Sharp Corporation.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 4.9 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


(Multiple Venders)
  • (Multiple Products)

A wide range of products are affected by this vulnerability.
As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors.
Impact

If the affected MFP processes a specially crafted request sent by an attacker who can access its Web management interface, sensitive information stored in the MFP may be obtained.
Solution

[Update the firmware]
Apply the appropriate firmware update provided by the respective developers.

[Apply workaround]
Applying appropriate workarounds provided by the respective developers may mitigate the impact of this vulnerability.

For more details, refer to the information provided by the respective developers.
Vendor Information

Sharp Corporation FUJIFILM Business Innovation Corp. (former Fuji Xerox Co., Ltd.)
CWE (What is CWE?)

  1. Path Traversal(CWE-22) [Other]
CVE (What is CVE?)

  1. CVE-2026-78249
References

  1. JVN : JVNVU#90160989
Revision History

  • [2026/10/02]
      Web page was published