cvedb.io
CVE-2022-26111
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2022-04-25T15:15:49.733 · Last modified 2026-06-17T04:34:42.257

Summary

The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server.

Affected products

canon — irisnext

Does this affect you?

Add your gear to cvedb and we'll alert you only when canon ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.