Published:2026/07/31  Last Updated:2026/07/31

JVNVU#98759887
Multiple vulnerabilities in Sharp and Toshiba Tec MFPs

Overview

Sharp and Toshiba Tec MFPs (multifunction printers) contain multiple vulnerabilities.

Products Affected

As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed below.

Description

Sharp and Toshiba Tec MFPs (multifunction printers) contain multiple vulnerabilities listed below.

  • User authentication can be bypassed with crafted URLs (CWE-425)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 5.3
    • CVE-2026-60011
  • Incomplete cleanup of cached files (CWE-459)
    • CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 2.4
    • CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 2.4
    • CVE-2026-63545
  • Insecure initial configuration (CWE-1188)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5
    • CVE-2026-63563
    • The products for a certain market have been shipped with the user authentication feature disabled in the initial configuration, which means that the address book editing and a range of features related to Document Filing can be accessed without user authentication.
    • Products intended for the Japanese market are not affected by this vulnerability.

Impact

  • Image data stored to the affected product can be retrieved without authentication (CVE-2026-60011).
  • Some image data are cached internally when printing and left uncleared. They may be accessed later by other users (CVE-2026-63545).
  • If the affected product is used with the initial configuration, any user can access the address book and other resources without authentication (CVE-2026-63563).

Solution

CVE-2026-60011, CVE-2026-63545
Update the firmware
Apply the appropriate firmware update according to the information provided by the respective vendors.

CVE-2026-63563
Apply workaround
Apply workarounds according to the information provided by the respective vendors.

Vendor Status

Vendor Status Last Update Vendor Notes
Sharp Corporation Vulnerable 2026/07/31 Sharp Corporation website
Toshiba Tec Corporation Vulnerable 2026/07/31 Toshiba Tec Corporation website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

CVE-2026-60011 and CVE-2026-63563 were reported directly to Sharp Corporation by the following reporters.
- CVE-2026-60011: Mohamed Abdelhady of Cyber 50 Defense
- CVE-2026-63563: John Jackson

Sharp Corporation reported CVE-2026-63545 to JPCERT/CC.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-60011
CVE-2026-63545
CVE-2026-63563
JVN iPedia