CVE-2026-1585 Details
Description
An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.
A vulnerability exists in Canon IJ Scan Utility for Windows, versions 1.1.2 through 1.5.0, due to an unquoted executable path in a Windows service. This flaw may enable a local attacker to execute a malicious file with the service's privileges, particularly if the file path includes spaces.
Users are advised to install the latest MP Driver, which includes a patched version of IJ Scan Utility for Windows. The updated software can be downloaded from the Canon Software Download page. After installation, verify that IJ Scan Utility for Windows version 1.6.0 or higher is installed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 27, 2026CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://canon.jp/support/support-info/260226vulnerability-response | Canon Inc. | AdvisoryRemedyVendor |
| https://psirt.canon/advisory-information/cp2026-002/ | Canon Inc. | AdvisoryRemedyVendor |
| https://www.canon-europe.com/support/product-security/ | Canon Inc. | Vendor |
| https://www.usa.canon.com/support/canon-product-advisories/CPA2026-002-Vulnerability-Remediation-for-IJ-Scan-Utility-for-Windows | Canon Inc. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | Canon Inc. |
Affected Products
| Product | Versions |
|---|---|
| Canon IJ Scan Utility | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Canon Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | CVE Modified | Canon Inc. |
| Feb 27, 2026 | New CVE Received | Canon Inc. |
Volerion