Junglewise Threat Intelligence

CVE-2026-3869: Schneider Electric PLC authentication algorithm incorrect implementation

CVE-2026-3869 · Severity: info · Published 2026-09-11

Vendors: Schneider Electric.

Executive brief

A Programmable Logic Controller (PLC) from Schneider Electric contains a flaw in how it verifies user credentials and access controls. If an application project with lower privilege levels is running on the device, an attacker could potentially bypass authentication to gain unauthorized access, compromising the confidentiality and integrity of industrial control operations.

Technical details

The vulnerability is an incorrect implementation of an authentication algorithm (CWE-303) in Schneider Electric PLCs. The flaw allows authentication bypass when lower-privilege application projects are present on the device. An attacker with network or local access to the PLC could exploit this to circumvent authentication mechanisms and access protected functions or data. The vulnerability requires specific preconditions (lower application level present) but could result in complete loss of confidentiality, integrity, and availability of the PLC system. Patch availability and specific affected versions are not detailed in the available references.

Affected products

  • Schneider Electric PLC Unknown

Timeline

  • 2026-09-11: disclosed

References