CPE2026-055 – Vulnerability Remediation for uniFLOW Online Legacy UI – 23 September 2026
A vulnerability has been identified in the uniFLOW Online Legacy UI relating to the Reduced Function Login feature (CVE-2026-92378), which could retain a previous user session when the device entered "Service Offline" Emergency Mode. During an investigation of the Legacy UI, it was discovered that the login process contained a logic flaw associated with the Reduced Function Login mechanism. Under a specific sequence of actions, the session of a previously authenticated user could be retained on the device. As a result, User B, a subsequently authenticated user, could potentially be logged on to the device as User A, the previously authenticated user.
Canon and NT-ware take security vulnerabilities seriously and can confirm that we have received no reports of active exploitation of this vulnerability. NT-ware has implemented a global fix to ensure correct login behaviour across all deployments. As the remediation has already been applied globally, no further action is required from customers.
Further details regarding the vulnerability, affected versions, and the globally deployed fix can be found at:
Security Advisory: Previous login session retained when entering Reduced Function Login