CVE-2026-78229: Command Injection
Published Sep 30, 2026
·Updated
Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.
Affected Software
1 affected component
Image Scanner Driver for Linux
Event History
Sep 30, 2026
CVE Published
via MITRE·01:51 AM
Data Sourced
via MITRE·01:51 AM
DescriptionSeverity
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Linux systems with Image Scanner Driver for Linux installed are in scope. Exploitation requires an attacker to be able to log in to the affected system.
2
What level of access and interaction does exploitation require?
The vector is local, and the attacker needs low privileges on the system. Exploitation also requires user interaction and unspecified preparatory steps.
3
What could an attacker achieve if exploitation succeeds?
An attacker may execute arbitrary OS commands. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability.