PT-2026-94194 · Mitsubishi · Gx Works3+1
CVE-2026-15688
·
Published
2026-09-17
·
Updated
2026-09-20
CVSS v4.0
9.2
Critical
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric GX Works3 and Motion Control Setting (affected versions not specified)
Description
An incorrect implementation of the authentication algorithm allows a local attacker to bypass block password authentication. By executing the software and modifying part of the executable module in memory, an attacker can successfully authenticate even with an invalid password. This may enable the attacker to view, tamper with, destroy, or delete control programs. In industrial control system environments, this flaw can be used to pivot across operational networks to manipulate critical manufacturing processes.
Recommendations
Update the software to the latest patched version.
Move every affected project to security version 2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gx Works3
Motion Control Setting