CVE-2026-21409

MEDIUM

RICOH Streamline NX 3.5.1-24R3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved.

Scores

CVSS v3 5.9
EPSS 0.0001
EPSS Percentile 2.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
Ricoh Company, Ltd./RICOH Streamline NX 3.5.1 to 24R3
Published Jan 09, 2026
Tracked Since Feb 18, 2026