Junglewise Threat Intelligence

CVE-2026-0936: ABB B&R PVI

CVE-2026-0936 · Severity: high · CVSS 5 · Published 2026-05-05

Vendors: ABB.

Executive brief

ABB B&R PVI is a communication interface used in industrial automation to connect PC applications with controllers. A vulnerability in the client application's logging feature could allow a local user to access sensitive information, such as credentials, if logging has been manually enabled. This could lead to unauthorized access to industrial control systems or sensitive operational data.

Technical details

An 'Insertion of Sensitive Information into Log File' (CWE-532) vulnerability exists in the ABB B&R PVI client. The root cause is the improper handling of credential information, which is written to log files in plain text when the PVI client's logging function is active. An attacker must have local authenticated access to the system and the logging feature must be explicitly enabled by a user (it is disabled by default). If these conditions are met, the attacker can read the log files to harvest credentials processed by the application. The issue is resolved in PVI version 6.5.0.

Affected products

  • ABB B&R PVI < 6.5.0, 6.5.0

Timeline

  • 2026-01-29: disclosed: Initial vendor advisory release
  • 2026-05-05: advisory: CISA republication date

References