Junglewise Threat Intelligence

CVE-2026-22622: Eaton Tripp Lite PADM privilege escalation in session management interface

CVE-2026-22622 · Severity: high · CVSS 8.8 · Published 2026-07-30

Executive brief

A security vulnerability exists in the management software for Eaton Tripp Lite power distribution and backup devices. An authorized user with low-level access could exploit this flaw to gain full administrative control over the device. This could allow an attacker to disrupt power operations, modify critical settings, or use the device as a foothold within the corporate network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the session management interface of Eaton Tripp Lite PADM firmware. The flaw stems from improper input validation of parameters passed through the web-based management interface. A remote attacker with low-privileged credentials can exploit this by sending specially crafted requests to execute arbitrary commands on the underlying operating system. Successful exploitation results in a complete compromise of the device with unrestricted administrative access. The vulnerability affects PADM versions up to and including version 20.

Affected products

  • Eaton Tripp Lite series PADM firmware Versions 20 and prior

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats