Junglewise Threat Intelligence

CVE-2026-19438: ABB Mint Workbench I path traversal vulnerability

CVE-2026-19438 · Severity: high · CVSS 7.5 · Published 2026-09-23

Vendors: ABB.

Executive brief

ABB Mint Workbench I, a configuration and maintenance tool for industrial automation systems, contains a path traversal vulnerability that allows attackers to access files outside intended directories. An attacker exploiting this flaw could read sensitive configuration files, credentials, or other restricted data stored on the system running the workbench.

Technical details

The path traversal vulnerability in Mint Workbench I allows an attacker to escape directory restrictions by manipulating file paths (e.g., using "../" sequences), enabling unauthorized access to arbitrary files on the system. The vulnerability is exploitable over the network without requiring authentication or user interaction. Exploitation results in confidentiality compromise through unauthorized file access.

Affected products

  • ABB Mint Workbench I through 5876

Timeline

  • 2026-09-23: disclosed

References