CVE-2026-26050

7.8

Ricoh · RICOHジョブログ集計ツール (RICOH Job Log Aggregation Tool)

An uncontrolled DLL search path vulnerability in the RICOH Job Log Aggregation Tool installer allows local attackers to execute arbitrary code with administrative privileges.

Executive summary

A critical DLL hijacking vulnerability in the RICOH Job Log Aggregation Tool installer could allow local attackers to achieve arbitrary code execution with administrative privileges.

Vulnerability

This vulnerability involves an uncontrolled search path element (CWE-427) within the software installer. An attacker can place a malicious Dynamic Link Library in a location where the installer incorrectly searches for dependencies, leading to code execution upon installation or update.

Business impact

Successful exploitation allows an attacker with local access to gain full administrative control over the affected system. This level of compromise enables the installation of malware, theft of sensitive credentials, and complete exfiltration of data, leading to severe operational disruption and potential regulatory non-compliance. The CVSS score of 7.8 confirms a high risk, particularly in multi-user or shared workstation environments where local access may be achievable.

Remediation

Immediate Action: Update the RICOH Job Log Aggregation Tool to version 1.3.7 or later as provided by the vendor.

Proactive Monitoring: Review system logs for unauthorized software installation attempts or unexpected file modifications in directories associated with the application installer.

Compensating Controls: Restrict local user permissions to prevent unauthorized file placement in system directories and utilize endpoint protection software to detect and block suspicious DLL loading behavior.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise through administrative privilege escalation, it is imperative that organizations running the RICOH Job Log Aggregation Tool prioritize the upgrade to version 1.3.7. Administrators should ensure that software installation processes are performed from secure, read-only media or verified locations to mitigate the risk of DLL hijacking during the update cycle.

Sources