Junglewise Threat Intelligence

CVE-2026-9260: Canon EOS Network Setting Tool hard-coded cryptographic keys

CVE-2026-9260 · Severity: medium · CVSS 6.2 · Published 2026-06-16

Technologies: Canon EOS Network Setting Tool, Canon EOS Utility. Vendors: Canon.

Executive brief

The Canon EOS Network Setting Tool, a utility used to configure network connections for Canon cameras, contains a security flaw where encryption keys are permanently embedded in the software. If an attacker gains access to a user's computer, they could use these keys to decrypt and steal sensitive login credentials used for transferring photos via FTP or SFTP. This could lead to unauthorized access to the servers where a photographer or organization stores their media.

Technical details

The Canon EOS Network Setting Tool (versions 1.5.0 and earlier) utilizes hard-coded cryptographic keys (CWE-321) within its binary. This vulnerability affects the software's FTP, FTPS, and SFTP communication test functions. A local attacker with access to the system can extract these static keys to decrypt stored authentication information. The flaw is present in both Windows and macOS versions of the tool, which is distributed as part of the EOS Utility suite (versions 3.12.0 through 3.20.20). Canon has released EOS Utility version 3.20.21 to address this issue.

Affected products

  • Canon EOS Network Setting Tool (included in EOS Utility) 1.5.0 and earlier (EOS Utility Ver.3.12.0 to Ver.3.20.20)

Timeline

  • 2026-06-15: disclosed: Initial disclosure by Canon Inc.
  • 2026-06-15: patched: Fix released in EOS Utility Ver.3.20.21
  • 2026-06-16: advisory: NVD publication date

References

Related threats