Executive brief
ABB Ability OPTIMAX is an energy management and optimization platform used in critical infrastructure sectors like energy and water. A security flaw in how the system handles Azure Active Directory Single-Sign On (SSO) could allow an unauthorized person to bypass login requirements. If exploited, an attacker could gain access to the management interface, potentially disrupting operations or accessing sensitive utility data.
Technical details
The vulnerability is classified as an Incorrect Implementation of Authentication Algorithm (CWE-303) within the Azure Active Directory Single-Sign On (SSO) integration of ABB Ability OPTIMAX. An attacker can exploit this flaw to bypass authentication mechanisms and gain unauthorized access to the system. The attack vector is network-based and requires no prior privileges or user interaction, though it is noted to have high attack complexity. Affected versions include 6.1, 6.2, and specific sub-versions of 6.3 and 6.4. ABB has released patches for versions 6.3 and 6.4 to remediate the issue.
Affected products
- ABB Ability OPTIMAX 6.1 all versions
- ABB Ability OPTIMAX 6.2 all versions
- ABB Ability OPTIMAX 6.3 versions prior to 6.3.1-251120
- ABB Ability OPTIMAX 6.4 versions prior to 6.4.1-251120
Timeline
- 2026-04-30: advisory: CISA published advisory ICSA-26-120-04
- 2026-04-30: disclosed: Initial republication of ABB PSIRT 9AKK108472A1331