CVE-2026-6891
MEDIUMCanon Inc. MY Image Garden For macOS - Improper Link Resolution Before File Access ('Link Following')
Title source: ruleDescription
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
https://psirt.canon/advisory-information/cp2026-004/
Vendor Advisory vendor-advisory
https://canon.jp/support/support-info/260528-2vulnerability-response
Vendor Advisory vendor-advisory
https://www.usa.canon.com/support/canon-product-advisories/CPA2026-004-Vulnerability-Remediation-for-My-Image-Garden-for-macOS-and-CUPS-Printer-Driver-for-macOS
Vendor Advisory vendor-advisory
https://www.canon-europe.com/support/product-security/
Scores
CVSS v3
5.0
EPSS
0.0012
EPSS Percentile
2.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-59
Status
published
Products (1)
Canon Inc./My Image Garden for macOS
3.6.8 or earlier
Published
May 29, 2026
Tracked Since
May 29, 2026