Junglewise Threat Intelligence

CVE-2026-1759: Secomea GateManager privilege escalation in permissions handling

CVE-2026-1759 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Secomea GateManager is an industrial remote access gateway that manages secure connectivity for operational technology environments. A privilege escalation vulnerability allows an authenticated attacker to bypass permissions controls and gain elevated access, potentially compromising the integrity and availability of critical industrial systems.

Technical details

The vulnerability is an improper handling of permissions and privileges in Secomea GateManager versions 11.5.0 and 11.4.625515072. The exact attack vector and preconditions are not detailed in the advisory, but the CVSS score of 6.5 suggests network or adjacent access may be involved. The flaw allows privilege escalation, enabling an attacker to exceed their authorization level within the application. Patched versions are available: GateManager 11.6 or 11.4.626194074 and above.

Affected products

  • Secomea GateManager 11.5.0, 11.4.625515072

Timeline

  • 2026-09-15: disclosed

References

Related threats