CVE-2026-56809 Details
Description
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.
A reflected cross-site scripting vulnerability has been identified in multiple laser printers and multifunction printers (MFPs) that implement Ricoh Web Image Monitor, version 1.00J. This vulnerability allows an attacker to execute arbitrary scripts in the web browser of a user accessing the Web Image Monitor.
Users are advised to update Web Image Monitor to the latest version. Specific guidance can be found on the Ricoh vulnerability details page linked in the References section.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2026-000005 | [email protected] | AdvisoryBundleRemedyVendor |
| https://jvn.jp/en/jp/JVN48718197/ | [email protected] | AdvisoryRemedy |
| https://www.konicaminolta.jp/business/support/important/260831_01_01.html | [email protected] | |
| https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-000005 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ricoh IM 430F | All versions |
CPE
Remediation
| |
| Ricoh IP 500SF | All versions |
CPE
Remediation
| |
| Ricoh Pro 8320S | All versions |
CPE
Remediation
| |
| Ricoh Pro 8310S | All versions |
CPE
Remediation
| |
| Ricoh Pro 8300S | All versions |
CPE
Remediation
| |
| Ricoh IM C7010 | All versions |
CPE
Remediation
| |
| Ricoh IM C3510 | All versions |
CPE
Remediation
| |
| Ricoh IM C3010 | All versions |
CPE
Remediation
| |
| Ricoh IM C2510 | All versions |
CPE
Remediation
| |
| Ricoh IM C2010 | All versions |
CPE
Remediation
| |
| Ricoh IM C6010 | All versions |
CPE
Remediation
| |
| Ricoh IM C5510 | All versions |
CPE
Remediation
| |
| Ricoh IM C4510 | All versions |
CPE
Remediation
| |
| Ricoh IM C431 | All versions |
CPE
Remediation
| |
| Ricoh IM C431F | All versions |
CPE
Remediation
| |
| Ricoh IM C3010SD | All versions |
CPE
Remediation
| |
| Ricoh IM C4510SD | All versions |
CPE
Remediation
| |
| Ricoh IM C6010SD | All versions |
CPE
Remediation
| |
| Ricoh Pro C5400S | All versions |
CPE
Remediation
| |
| Ricoh Pro C5410S | All versions |
CPE
Remediation
| |
| Ricoh Pro 8420S | All versions |
CPE
Remediation
| |
| Ricoh Pro 8410S | All versions |
CPE
Remediation
| |
| Ricoh Pro 8400S | All versions |
CPE
Remediation
| |
| Ricoh IM C300 | All versions |
CPE
Remediation
| |
| Ricoh MP CW1201 | All versions |
CPE
Remediation
| |
| Ricoh MP CW2201 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion