CVE 5.9 MEDIUM

CVE-2026-21409_CVE-2026-21409

5.9 / 10
MEDIUM
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved.

Basic Information

ID CVE-2026-21409
Source jpcert
Published Jan 9, 2026 at 07:15

Affected Product

Vendor Ricoh Company, Ltd.
Product RICOH Streamline NX
Version 3.5.1 to 24R3
Affected Versions Ricoh Company, Ltd. RICOH Streamline NX 3.5.1 to 24R3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.