CP2026-007 Vulnerability in PRISMAproduction

CP2026-007 Vulnerability in PRISMAproduction

July 30, 2026
Canon Production Printing
 
 
Description
A deserialization vulnerability has been identified in PRISMAproduction. This vulnerability could allow an unauthenticated attacker on an adjacent network to execute arbitrary code.
 
Affected Product
PRISMAproduction Version 6.5 or earlier.

Remediation
A fix patch (Version 6.5.1 or later) is available. Installation of the patch requires assistance from Service & Support personnel. Please contact your local or regional Canon Service & Support representative to arrange installation.

CVE/CVSS

CVE-2026-3245: A deserialization vulnerability in PRISMAproduction that may lead to arbitrary code execution CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score: 7.7
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Base Score: 7.5
 
Thank you to Anton Fabricius and Moritz Bechler of SySS GmbH for reporting this vulnerability.