CVE-2026-3245

Canon Production Printing · PRISMAproduction

A deserialization of untrusted data vulnerability exists in Canon Production Printing PRISMAproduction version 6.5 and earlier.

Executive summary

A deserialization vulnerability in PRISMAproduction could allow an adjacent attacker to achieve unauthorized code execution or system impact.

Vulnerability

This is a deserialization of untrusted data flaw (CWE-502) that allows for the execution of arbitrary code or other malicious operations. The attack vector is identified as adjacent, meaning the attacker must be on the same local network segment.

Business impact

Successful exploitation allows an attacker to compromise the integrity and availability of the PRISMAproduction system. Given the CVSS score of 7.5, this vulnerability represents a severe threat to production environments, potentially causing significant operational downtime or data loss.

Remediation

Immediate Action: Apply the vendor-provided security updates available through the Canon Production Printing support portal.

Proactive Monitoring: Monitor network traffic for unusual deserialization patterns or unexpected process execution within the PRISMAproduction environment.

Compensating Controls: Implement network segmentation to isolate the PRISMAproduction software from untrusted network segments, limiting the reach of potential adjacent attackers.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for code execution, organizations should prioritize patching their PRISMAproduction software. Ensure that all security advisories from Canon are reviewed and that the recommended updates are tested and deployed in accordance with organizational maintenance windows.