Printers Have Path Traversal Vulnerability

Fujifilm and Sharp multifunction printers are impacted by a flaw allowing unauthorized data access.

Updated on Sept. 30, 2026 in Cybersecurity

Isometric editorial illustration of a modular office printer as a geometric, sculptural object in an uncluttered, technical setting.
Fujifilm and Sharp have confirmed a critical path traversal vulnerability in their multifunction printer lines that allows unauthorized access to data. AI Illustration. Upload story photo >

Live Poll

Do you prioritize installing firmware updates for connected devices in your home?

A path traversal vulnerability has been identified in multifunction printers manufactured by FUJIFILM Business Innovation and Sharp Corporation. The flaw allows attackers with access to the Web management interface to obtain sensitive information from the devices.

Why it matters

The vulnerability poses a security risk to organizations using these printers, as attackers could potentially exfiltrate confidential data stored on or accessed through the units. Swift action by administrators to update firmware is critical to preventing unauthorized exploitation.

The vulnerability is tracked under report ID JVNVU#90160989. It enables unauthorized file access when the device processes a specially crafted request sent via the Web management interface.

The players

FUJIFILM Business Innovation Corp

This company is a major manufacturer of office equipment and digital printing solutions that reported the vulnerability to security authorities.

Sharp Corporation

This global electronics manufacturer produces a range of multifunction printer models that have been identified as susceptible to this security flaw.

JPCERT/CC

This organization serves as the coordination center for computer emergency response in Japan and handled the reporting of the vulnerability.

The details

The flaw exists within the Web management interface of affected Fujifilm and Sharp multifunction printers. By sending a malicious, specially crafted request, an unauthorized attacker can traverse the file system to retrieve sensitive information that should otherwise be protected.

Timeline

  1. The vulnerability notification was officially published on September 30, 2026.

The Big Picture

This security disclosure follows the standardized communication patterns established by the JPCERT/CC vulnerability disclosure protocol. These processes are essential for maintaining global cybersecurity standards as office hardware becomes increasingly integrated with networked software.

Users and IT administrators should prioritize installing the latest firmware updates provided by Fujifilm and Sharp to eliminate this security gap. If immediate updates are not possible, administrators should consult the developers for recommended workarounds to mitigate exposure.

The takeaway

Organizations should perform routine audits of all network-connected office hardware to ensure firmware is current. Proactive patch management remains the most effective defense against localized path traversal and remote access threats.

Further reading

For more information on securing office network hardware, visit our Cybersecurity section.

Source note: This article includes information reported by Jvn.

Live Poll

Do you prioritize installing firmware updates for connected devices in your home?