CVE-2026-56809

MEDIUM

Ricoh Web Image Monitor - Reflected Cross-Site Scripting

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-56809. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-56809, a reflected XSS vulnerability in Ricoh Web Image Monitor implemented in multiple laser printers and MFPs. The code includes placeholder logic for target probing but lacks actual exploit implementation.

Description

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-56809_multiple_laser_printers.py

This repository contains an auto-generated stub module for CVE-2026-56809, a reflected XSS vulnerability in Ricoh Web Image Monitor implemented in multiple laser printers and MFPs. The code includes placeholder logic for target probing but lacks actual exploit implementation.

Classification
Stub 99%
Attack Type
Xss
Complexity
Moderate
Reliability
Theoretical
Target: Ricoh Web Image Monitor (multiple laser printers and MFPs)
No auth needed
Prerequisites: Network access to the target printer's web interface (default port 80/443)
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 8.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Ricoh Company, Ltd./Multiple laser printers and MFPs which implement Ricoh Web Image Monitor see the information provided by the vendor
Published Jun 30, 2026
Tracked Since Jun 30, 2026