Junglewise Threat Intelligence

CVE-2026-11833: Yokogawa FAST/TOOLS and CI Server information disclosure in web server

CVE-2026-11833 · Severity: info · CVSS 8.2 · Published 2026-06-23

Executive brief

Yokogawa FAST/TOOLS and CI Server, which are used for industrial automation and supervisory control, contain a vulnerability where the web server may leak sensitive configuration settings. An attacker could use this information to gain insights into the system's internal setup, potentially facilitating more targeted and damaging attacks against the industrial infrastructure. This could lead to unauthorized access or disruption of critical operations if the leaked data is used to bypass other security measures.

Technical details

A sensitive information disclosure vulnerability exists in Yokogawa FAST/TOOLS and CI Server due to the cleartext transmission or improper handling of configuration data (CWE-319). The web server component may include CI Server setting information within its responses to network requests. This vulnerability is reachable over the network without authentication, though the CVSS 4.0 score suggests some level of technical prerequisite (AT:P). An attacker can capture or solicit these responses to obtain internal system details, which can be used as a precursor for more complex exploitation. Affected versions include FAST/TOOLS R9.01 through R10.04 and CI Server R1.01 through R1.04.

Affected products

  • Yokogawa Electric Corporation FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04
  • Yokogawa Electric Corporation CI Server (All packages) R1.01 to R1.04

Timeline

  • 2026-06-23: advisory: Initial publication of the advisory by Yokogawa and NVD.

References