PT-2026-94194 · Mitsubishi · Gx Works3+1

CVE-2026-15688

·

Published

2026-09-17

·

Updated

2026-09-20

CVSS v4.0

9.2

Critical

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric GX Works3 and Motion Control Setting (affected versions not specified)
Description An incorrect implementation of the authentication algorithm allows a local attacker to bypass block password authentication. By executing the software and modifying part of the executable module in memory, an attacker can successfully authenticate even with an invalid password. This may enable the attacker to view, tamper with, destroy, or delete control programs. In industrial control system environments, this flaw can be used to pivot across operational networks to manipulate critical manufacturing processes.
Recommendations Update the software to the latest patched version. Move every affected project to security version 2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15688

Affected Products

Gx Works3
Motion Control Setting