CVE-2026-92378 Details
Description
A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.
A session management vulnerability has been identified in the Legacy UI Reduced Function Login feature of Canon NT-ware uniFLOW Online. During Service Offline Emergency Mode, a previously authenticated session may be retained after logout, allowing a subsequent user to be authenticated as the previous user and gain unauthorized limited access to device functionality.
NT-ware has implemented a global fix for this vulnerability in uniFLOW Online. No further action is required from customers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ntware.atlassian.net/wiki/spaces/SA/pages/14160592897/Security+Advisory+Previous+login+session+retained+when+entering+Reduced+Function+Login | Canon_EMEA | AdvisoryPermission RequiredVendor |
| https://www.canon-europe.com/psirt/advisory-information/ | Canon_EMEA | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | Canon_EMEA |
Affected Products
| Product | Versions |
|---|---|
| NT-ware uniFLOW Online | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | Canon_EMEA |
Volerion