Executive brief
ABB Mint Workbench I, a configuration and maintenance tool for industrial automation systems, contains a path traversal vulnerability that allows attackers to access files outside intended directories. An attacker exploiting this flaw could read sensitive configuration files, credentials, or other restricted data stored on the system running the workbench.
Technical details
The path traversal vulnerability in Mint Workbench I allows an attacker to escape directory restrictions by manipulating file paths (e.g., using "../" sequences), enabling unauthorized access to arbitrary files on the system. The vulnerability is exploitable over the network without requiring authentication or user interaction. Exploitation results in confidentiality compromise through unauthorized file access.
Affected products
- ABB Mint Workbench I through 5876
Timeline
- 2026-09-23: disclosed