CPA2026-006: Multiple Vulnerabilities in Data Collection Agent
July 23, 2026
Multiple vulnerabilities have been identified in a component used by the Data Collection Agent*. If exploited, these vulnerabilities could potentially result in impacts such as denial of service (DoS) attacks or exposure of credentials used for proxy connections.
* This component is used only when [Monitoring Mode] is set to "CCA mode"; therefore, the Data Collection Agent is not affected by these vulnerabilities when [Monitoring Mode] is set to "Standard mode".
There have been no reports of these vulnerabilities being exploited. However, to enhance the security of the product, we advise that our customers install the latest Data Collection Agent.
We will continue to further strengthen our security measures to ensure that you can continue using Canon products with peace of mind. If these vulnerabilities are identified in other products, we will update this article.
Please note the affected software is Data Collection Agent Versions 2.0.2 to 2.0.4 (inclusive) and is only impacted when [Monitoring Mode] is set to "CCA mode".
An updated version of the Data Collection Agent (Version 2.0.5 or later) has been made available to address these vulnerabilities. Installation requires support from Service & Support personnel. Please contact your local Canon sales company for further information and guidance.
CVE
The following CVEs are addressed in this advisory:
- CVE-2025-62168
- CVE-2024-45802
- CVE-2024-37894
- CVE-2024-25617
- CVE-2024-25111
- CVE-2023-49286
- CVE-2023-49285
- CVE-2022-41317
- CVE-2021-46784
- CVE-2021-33620
- CVE-2021-31808
- CVE-2021-31807
- CVE-2021-31806