CVE-2026-6891
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
5.0 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Vulnerability Description
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-59
Source
NVD
External References
- https://canon.jp/support/support-info/260528-2vulnerability-response
- https://psirt.canon/advisory-information/cp2026-004/
- https://www.canon-europe.com/support/product-security/
- https://www.usa.canon.com/support/canon-product-advisories/CPA2026-004-Vulnerability-Remediation-for-My-Image-Garden-for-macOS-and-CUPS-Printer-Driver-for-macOS
Discussion (0)
Add Comment
No comments yet. Be the first!