Junglewise Threat Intelligence

CVE-2026-30512: Scheidt & Bachmann entervo HMI privilege escalation via kiosk mode escape

CVE-2026-30512 · Severity: high · CVSS 7.8 · Published 2026-08-24

Executive brief

Scheidt & Bachmann entervo HMI is a human-machine interface system used to control industrial processes. A vulnerability in its restricted-access kiosk mode allows an authenticated user with limited privileges to escape the locked environment and gain administrator-level control by exploiting the PDF viewer's print function. This could allow an attacker to run arbitrary commands and potentially take over the entire system.

Technical details

The vulnerability is an improper access control flaw (CWE-284) in the Restricted Access (Kiosk) Mode implementation of entervo HMI. It affects the external PDF viewer used to display application manuals and its interaction with the Windows operating system. An authenticated low-privileged user can exploit the PDF viewer's print functionality to escape the kiosk environment and execute arbitrary commands with local administrator privileges. Attack requires local access and prior authentication. No public exploits are known at the time of publication, and patches are available in version V2 R5 P0 M5 and later.

Affected products

  • Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5

Timeline

  • 2026-08-24: disclosed
  • 2026-08-03: other: Details published on GitHub

References