Junglewise Threat Intelligence

CVE-2026-15688: Mitsubishi Electric GX Works3 authentication bypass in block password

CVE-2026-15688 · Severity: high · CVSS 8.8 · Published 2026-09-17

Executive brief

Mitsubishi Electric GX Works3 and Motion Control Settings are software tools used to program and configure industrial control systems in manufacturing environments. A flaw in how the software validates block passwords allows a local attacker to bypass password protection and gain unauthorized access to modify control programs. Successful exploitation could enable tampering with, destroying, or deleting critical industrial control logic, potentially disrupting manufacturing operations.

Technical details

This is an incorrect implementation of authentication algorithm vulnerability (CWE-303) in Mitsubishi Electric GX Works3 and Motion Control Settings. The affected products fail to properly validate block passwords, allowing a local attacker to execute the product and modify executable modules in memory, thereby circumventing password-based access controls. The attack vector is local with low privilege requirements and no user interaction needed. The vulnerability permits an attacker to view, tamper with, destroy, or delete control programs used in industrial control systems. Patches are available: GX Works3 version 1.096A or later and Motion Control Settings version 1.070Y or later include a security version setting that must be configured to version "2" to remediate the issue.

Affected products

  • Mitsubishi Electric GX Works3 all versions
  • Mitsubishi Electric Motion Control Settings all versions

Timeline

  • 2026-09-17: disclosed

References