CVE-2026-41226 MEDIUM

CVE-2026-41226

Vendor Ricoh Company, Ltd.
Product Multiple laser printers and MFPs which implement Web Image Monitor
Weakness CWE-601 · Open redirect
Published April 30, 2026
Last update May 1, 2026

CVSS base score

4.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.

Key dates

02Disclosure timeline

April 30, 2026 CVE published
May 1, 2026 Record updated