Patch Priorities for CVE-2026-78249: What MFP Owners Should Do First
Vulnerability overview
CVE-2026-78249 is a path traversal vulnerability in multifunction printers from FUJIFILM Business Innovation Corp. and Sharp Corporation. JPCERT/CC published the coordinated advisory as JVNVU#90160989 on 2026-09-30, listing both vendors as affected.
The flaw is CWE-22 with a CVSS v4.0 base score of 6.9 and a CVSS v3.1 base score of 4.9. The v4.0 vector, AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N, describes a network-reachable issue with a confidentiality-only outcome.
Mechanism and exploitation conditions
The device fails to constrain a caller-supplied pathname to a permitted directory. When someone who can reach the web management interface sends a crafted request, the device can process a path outside its intended boundary, and sensitive information stored on the MFP may be obtained.
JVN does not publish the request format or the file set that is reachable. What the advisory does establish is that access to the management interface is part of the exploitation path, and the v4.0 privileges value of High is consistent with that.
Impact
The consequence is disclosure of data held on the device, with no reported integrity or availability effect. For an organisation, the relevant question is what its printers store and who can reach their consoles, not whether the device can be taken down.
Affected products and scope
JVN states that multiple MFPs from FUJIFILM Business Innovation Corp. and Sharp Corporation are affected and that a wide range of products is in scope, while explicitly deferring product names, models, and versions to the vendors. Both vendors appear as Vulnerable with a last update of 2026-09-30.
Exposure context
A verified ZoomEye observation for this topic:
- Search Dork:
app="FUJIFILM" || app="Sharp" - Exposure: 22,608 instances identified globally This measures assets matching the vendor fingerprints, which helps size the fleet of interest. It does not indicate firmware versions or confirm which units are vulnerable.
Remediation and mitigations
JVN lists two remedies. The solution is to apply the appropriate firmware update provided by the respective vendors. The supporting mitigation is to apply the workarounds those vendors publish.
A workable order of operations follows from the vector. First, determine which models you actually own and map them to vendor guidance, since the advisory does not provide the model matrix. Second, apply firmware updates on the devices whose consoles are reachable from untrusted segments before those confined to management networks. Third, where an update cannot be staged immediately, apply vendor workarounds and tighten who can reach the web management interface.
Verification should be vendor-led. Because the advisory publishes no version-level detail, confirmation that a device is patched comes from vendor documentation, not from a scan.
References
- JVNVU#90160989, JPCERT/CC/JVN, published 2026-09-30: https://jvn.jp/en/vu/JVNVU90160989/index.html
- FUJIFILM Business Innovation Corp. vendor information
- Sharp Corporation vendor information
Top comments (0)