Response to vulnerability in some Toshiba Tec's
digital multi-function peripherals

July 31st, 2026
Toshiba Tec Corporation

Thank you for using our products.

The following vulnerabilities have been identified in some of our multi-function peripherals. If this vulnerability is exploited, there is a risk of information disclosure. Currently, we have not confirmed any incidents involving the exploitation of this vulnerability or any leakage of information from affected products.
We strongly recommend that customers implement the solution or mitigation measures described in this advisory.

Vulnerability details

Target Products : e-STUDIO 908/ 1058/ 1208, e-STUDIO 907/ 1057/ 1207
(These products have been sold only in the North American market.)
For more information, see the reference sites below (Jump to another website with opening new window.)

Reference Reference site
CVE-2026-60011
JVNVU#98759887
https://www.cve.org/CVERecord?id=CVE-2026-60011
User authentication can be bypassed with crafted URLs
CVE-2026-63545
JVNVU#98759887
https://www.cve.org/CVERecord?id=CVE-2026-63545
Incomplete cleanup of cached files
CVE-2026-63563
JVNVU#98759887
https://www.cve.org/CVERecord?id=CVE-2026-63563
The products for a certain market have been shipped with the user authentication feature disabled in the initial configuration, which means that the address book editing and a range of features related to Document Filing can be accessed without user authentication.

Countermeasure

Regarding CVE-2026-60011 and CVE-2026-63545, ask your service company to update the main unit software. Regarding CVE-2026-63563, see “Mitigation measures” below to restrict device web page access via password.

Mitigation measures

To mitigate the security risks, ensure to protect your MFPs and apply the following operations:

  • Change the default Administrator and the default User passwords from factory default and manage them appropriately.
  • Do not connect MFPs directly to the Internet. Connect them via a firewall or similar network appliance.
  • Restrict device web page access via password (enable [System Settings]-[Security Settings]-[Restrict Device Web Page Access Via Password]).
  • Monitor the MFP periodically using the Audit Log functionality to see if suspicious access is observed.

If the above operational mitigations are not practiced, the risks of the vulnerabilities being exploited increases.

Acknowledgements

CVE-2026-60011 and CVE-2026-63563 were reported by the following reporters.
- CVE-2026-60011: Mohamed Abdelhady of Cyber 50 Defense
- CVE-2026-63563: John Jackson
We would like to express our sincere appreciation for the disclosure responsible.