Unrated severityNVD Advisory· Published Sep 23, 2026
uniFLOW Online Legacy UI Previous login session retained when entering Reduced Function Login
CVE-2026-92378
Description
A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.
Patches
Vulnerability mechanics
References
2- ntware.atlassian.net/wiki/spaces/SA/pages/14160592897/Security+Advisory+Previous+login+session+retained+when+entering+Reduced+Function+Loginmitrevendor-advisorymitigation
- www.canon-europe.com/psirt/advisory-information/mitrevendor-advisory
News mentions
0No linked articles in our index yet.