CVE-2026-60011
Received Received - Intake

Authentication Bypass in Sharp and Toshiba Tec MFPs

Vulnerability report for CVE-2026-60011, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: JPCERT/CC

Description

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
sharp mfp *
toshiba_tec mfp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-425 The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Sharp and Toshiba Tec multifunction printers (MFPs) do not properly authorize requests to access stored image data. This means unauthorized users might retrieve sensitive documents or images without authentication.

Detection Guidance

Check for unauthorized access to image data on Sharp and Toshiba Tec MFPs by monitoring network traffic to these devices for unusual requests targeting image storage endpoints. Inspect logs for direct access attempts to image data paths.

Impact Analysis

Attackers could exploit this to steal confidential documents, images, or other sensitive data stored on the printer. This may lead to data breaches, privacy violations, or unauthorized access to internal information.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data without authorization. For HIPAA, it may risk protected health information (PHI) exposure. Non-compliance may lead to legal penalties or fines.

Mitigation Strategies

Restrict network access to affected MFPs by implementing firewall rules to block unauthorized requests. Update firmware to the latest version provided by the vendor. Disable direct access to image data storage if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60011. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart