CVE-2026-6891: Canon Inc My Image Garden For macOS
Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
Affected products
- Canon Inc My Image Garden For macOS: up to and including 3.6.8
Published 2026-05-29. Last modified 2026-07-21.