Get instant answers to issues or questions anytime - try our new AI Support Assistant.×

ShareScan - CVE-2026-34477 and CVE-2026-34480

Home›Search›ShareScan - CVE-2026-34477 and CVE-2026-34480

ShareScan - CVE-2026-34477 and CVE-2026-34480

Last Updated: Sep 11, 2026|2 minute read|000045101
#ShareScan#Knowledge#Troubleshooting

Overview

eCopy ShareScan versions 6.6, 6.7, and 2025.3 currently include Apache Log4j version 2.17.1. Based on current development analysis, the practical exposure depends on the device environment and whether optional components such as Ricoh support or the ShareScan web client are actively used.

The upcoming eCopy ShareScan 2026.3 release will include updated Log4j libraries addressing the reported vulnerabilities.

Vulnerabilities

  • CVE-2026-34477
  • CVE-2026-34480

Current Product Assessment

  • Environments using only Canon devices are not actively using the affected Log4j components located within the Ricoh deployment path or the ShareScan web client components.
  • Apache Tomcat is not required for the Canon eCopy ShareScan client.
  • Ricoh functionality and the optional web client may still rely on the included Log4j libraries.

The actual exposure therefore depends on which ShareScan components and device integrations are deployed.

Temporary Mitigation Options

Canon-Only Environments

If the environment uses Canon devices only and does not require:

  • Ricoh device support
  • ShareScan web client functionality

then the Log4j libraries located in the Ricoh deployment path are not actively used.

Under these conditions, the following files may be removed from the Ricoh deployment folder without impacting Canon device functionality:

Files to Remove

  • log4j-api-2.17.1.jar
  • log4j-core-2.17.1.jar

File Location

<ShareScan Installation Folder>\Server\DeviceRegistration\plugins\Ricoh\Deployment\lib

Typical path:

C:\Program Files (x86)\Tungsten\ShareScan6.6\Server\DeviceRegistration\plugins\Ricoh\Deployment\lib

Manual Log4j Library Replacement

A manual replacement of Log4j libraries may technically be possible, similar to the mitigation previously documented for CVE-2021-44228.

However:

  • Log4j 2.25.4 has not yet been officially validated with the currently released ShareScan versions.
  • Manual replacement is therefore not officially certified at this time.
  • Customers performing manual replacement do so at their own risk.
  • Functional validation is required after replacement, particularly for:
    • Ricoh integrations
    • ShareScan web client functionality
    • Tomcat-based deployments

If functionality issues occur after manual library replacement, updated binaries from Development may be required.

Ricoh and Web Client Considerations

Ricoh Environments

If Ricoh device support is required:

  • the Log4j libraries must remain in place unless updated replacement binaries are provided.

ShareScan Web Client

If the ShareScan web client is used:

  • updated ShareScan web client components may be required to fully address the vulnerability.

Permanent Resolution

The planned eCopy ShareScan 2026.3 release will include updated Apache Log4j components.

Updated Version

  • Apache Log4j 2.25.4

Summary

Current findings indicate that the practical exposure depends on the deployed ShareScan components and device integrations. For Canon-only environments without Ricoh support or web client usage, the affected Log4j libraries are not actively used according to current development analysis.

Manual replacement of Log4j libraries may technically be possible but is not currently an officially validated procedure for the affected ShareScan releases.

A permanent product-level fix is planned in eCopy ShareScan 2026.3 with Apache Log4j 2.25.4.

Applies to  

ProductVersionBuildEnvironmentHardware
eCopy ShareScan6.6   
eCopy ShareScan6.7
eCopy ShareScan2025.3

References

Apache Log4j Security Advisories:


 

Was this topic helpful? Like Dislike