Published:2026/09/30  Last Updated:2026/09/30

JVNVU#90160989
Path traversal vulnerability in FUJIFILM Business Innovation and Sharp MFPs (multifunction printers)

Overview

FUJIFILM Business Innovation and Sharp MFPs (multifunction printers) contain a path traversal vulnerability.

Products Affected

A wide range of products are affected by this vulnerability.
As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors.

Description

Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Sharp Corporation contain a path traversal vulnerability.

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Base Score 4.9
    • CVE-2026-78249

Impact

If the affected MFP processes a specially crafted request sent by an attacker who can access its Web management interface, sensitive information stored in the MFP may be obtained.

Solution

Update the firmware
Apply the appropriate firmware update provided by the respective developers.

Apply workaround
Applying appropriate workarounds provided by the respective developers may mitigate the impact of this vulnerability.

For more details, refer to the information provided by the respective developers.

Vendor Status

Vendor Status Last Update Vendor Notes
FUJIFILM Business Innovation Corp. Vulnerable 2026/09/30 FUJIFILM Business Innovation Corp. website
Sharp Corporation Vulnerable 2026/09/30 Sharp Corporation website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

FUJIFILM Business Innovation Corp. reported this vulnerability to JPCERT/CC to notify users of the solution through JVN. JPCERT/CC coordinated with FUJIFILM Business Innovation Corp. and Sharp Corporation.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia