Insufficient Authorization in User Account Management of Affected Product by Vendor
CVE-2026-8046

7.2HIGH

What is CVE-2026-8046?

This vulnerability arises from the affected products' failure to properly verify user authorization when attempting to delete accounts. Consequently, an authenticated user with low privileges can exploit this oversight to delete accounts of other users, including those with higher privileges, potentially leading to significant disruption and unauthorized access to sensitive information.

Affected Version(s)

CODESYS Control for BeagleBone SL 3.0.0.0 < 4.21.0.0

CODESYS Control for emPC-A/iMX6 SL 3.0.0.0 < 4.21.0.0

CODESYS Control for IOT2000 SL 3.0.0.0 < 4.21.0.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB AG
.