5
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Description
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
Basic Information
ID
CVE-2026-6891
Source
Canon
Published
May 28, 2026 at 23:59
Affected Product
Vendor
Canon Inc.
Product
My Image Garden for macOS
Version
3.6.8 or earlier
Affected Versions
Canon Inc. My Image Garden for macOS 3.6.8 or earlier
CWE Classification
References
- psirt.canon /advisory-information/cp2026-004/
- canon.jp /support/support-info/260528-2vulnerability-response
- www.usa.canon.com /support/canon-product-advisories/CPA2026-004-Vulnerability-Remediation-for-My-Image-Garden-for-macOS-and-CUPS-Printer-Driver-for-macOS
- www.canon-europe.com /support/product-security/