CVE-2026-21409
Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21409?
CVE-2026-21409 has a high severity rating due to the potential for man-in-the-middle attacks that compromise user registration information and OpenID credentials.
How do I fix CVE-2026-21409?
To fix CVE-2026-21409, update RICOH Streamline NX to the latest version that addresses this vulnerability.
What products are affected by CVE-2026-21409?
CVE-2026-21409 affects RICOH Streamline NX versions 3.5.1 to 24R3.
What type of vulnerability is CVE-2026-21409?
CVE-2026-21409 is classified as an improper authorization vulnerability.
What could be the impact of CVE-2026-21409?
The impact of CVE-2026-21409 could lead to unauthorized access to user registration information and potential exploitation of OpenID Connect credentials.