CVE-2026-6891 Details
Description
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
A vulnerability exists in the installers of Canon My Image Garden for macOS, version 3.6.8 and earlier, and the CUPS Printer Driver for macOS. The issue arises from improper validation of symbolic links, which may allow a local attacker with login privileges to exploit a crafted symbolic link during installation. This could lead to unauthorized modification of file or directory permissions.
Users are advised to download and install the latest version of My Image Garden for macOS or the CUPS Printer Driver for macOS from the Canon Software & Drivers download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | Canon Inc. |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Canon Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | New CVE Received | Canon Inc. |