CVE-2026-1585
Severity CVSS v4.0:
HIGH
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
27/02/2026
Last modified:
27/02/2026
Description
An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
6.70
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://canon.jp/support/support-info/260226vulnerability-response
- https://psirt.canon/advisory-information/cp2026-002/
- https://www.canon-europe.com/support/product-security/
- https://www.usa.canon.com/support/canon-product-advisories/CPE2026-002-Vulnerability-Remediation-for-IJ-Scan-Utility-for-Windows



