Response to vulnerability in some Toshiba Tec's
digital multi-function peripherals
July 31st, 2026
Toshiba Tec Corporation
Thank you for using our products.
The following vulnerabilities have been identified in some of our multi-function peripherals. If this vulnerability is exploited, there is a risk of information disclosure. Currently, we have not confirmed any incidents involving the exploitation of this vulnerability or any leakage of information from affected products.
We strongly recommend that customers implement the solution or mitigation measures described in this advisory.
Vulnerability details
Target Products : e-STUDIO 908/ 1058/ 1208, e-STUDIO 907/ 1057/ 1207
(These products have been sold only in the North American market.)
For more information, see the reference sites below (Jump to another website with opening new window.)
| Reference | Reference site |
|---|---|
| CVE-2026-60011 JVNVU#98759887 |
https://www.cve.org/CVERecord?id=CVE-2026-60011 User authentication can be bypassed with crafted URLs |
| CVE-2026-63545 JVNVU#98759887 |
https://www.cve.org/CVERecord?id=CVE-2026-63545 Incomplete cleanup of cached files |
| CVE-2026-63563 JVNVU#98759887 |
https://www.cve.org/CVERecord?id=CVE-2026-63563 The products for a certain market have been shipped with the user authentication feature disabled in the initial configuration, which means that the address book editing and a range of features related to Document Filing can be accessed without user authentication. |
Countermeasure
Regarding CVE-2026-60011 and CVE-2026-63545, ask your service company to update the main unit software. Regarding CVE-2026-63563, see “Mitigation measures” below to restrict device web page access via password.
Mitigation measures
To mitigate the security risks, ensure to protect your MFPs and apply the following operations:
- Change the default Administrator and the default User passwords from factory default and manage them appropriately.
- Do not connect MFPs directly to the Internet. Connect them via a firewall or similar network appliance.
- Restrict device web page access via password (enable [System Settings]-[Security Settings]-[Restrict Device Web Page Access Via Password]).
- Monitor the MFP periodically using the Audit Log functionality to see if suspicious access is observed.
If the above operational mitigations are not practiced, the risks of the vulnerabilities being exploited increases.
Acknowledgements
CVE-2026-60011 and CVE-2026-63563 were reported by the following reporters.
- CVE-2026-60011: Mohamed Abdelhady of Cyber 50 Defense
- CVE-2026-63563: John Jackson
We would like to express our sincere appreciation for the disclosure responsible.












