Junglewise Threat Intelligence

CVE-2026-6892: Canon CUPS Printer Driver symbolic link vulnerability in macOS installer

CVE-2026-6892 · Severity: medium · CVSS 5 · Published 2026-05-29

Vendors: Canon.

Executive brief

A security issue exists in the installer for certain Canon printer drivers on macOS. This software is used to enable printing functionality for PIXMA and PIXUS series printers. If an attacker already has local access to a computer, they could use a specially crafted file link during the installation process to change the permissions of system folders they shouldn't be able to access, potentially compromising the integrity of the system.

Technical details

A vulnerability classified as CWE-59 (Improper Link Resolution Before File Access) exists in the installer for Canon CUPS Printer Drivers on macOS. The installer fails to properly validate symbolic links during the installation process. A local attacker with login privileges can exploit this by creating a specially crafted symbolic link that the installer follows, allowing the attacker to modify permissions of arbitrary directories for which they would not normally have authorization. This requires user interaction to run the installer. Canon has released updated driver versions to address this issue.

Affected products

  • Canon PIXUS iX6800 Series CUPS Printer Driver 16.91.0.0 or earlier
  • Canon PIXMA MG2500 Series CUPS Printer Driver 16.91.0.0 or earlier

Timeline

  • 2026-05-28: disclosed: Initial disclosure by Canon
  • 2026-05-29: advisory: NVD publication date

References