Authentication Algorithm Flaw in Mitsubishi Electric GX Works3 and Motion Control Settings
CVE-2026-15688

9.2CRITICAL

What is CVE-2026-15688?

A vulnerability in Mitsubishi Electric's GX Works3 and Motion Control Settings exposes systems to unauthorized access. A local attacker can exploit this flaw by successfully authenticating with an invalid block password. This is facilitated through modifications to the executable module in memory, potentially leading to unauthorized viewing, tampering, deletion, or destruction of control programs. The exploitation of this vulnerability poses significant risks to the integrity and availability of automated control systems.

Affected Version(s)

GX Works3 All versions

Motion Control Setting All versions

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.