Junglewise Threat Intelligence

CVE-2026-5434: Honeywell Control Network Module sensitive information disclosure

CVE-2026-5434 · Severity: medium · CVSS 5.9 · Published 2026-05-21

Vendors: Honeywell.

Executive brief

A vulnerability exists in the Honeywell Control Network Module (CNM), a component used in industrial automation environments to manage communications. The system incorrectly stores sensitive information in file directories that may be accessible to unauthorized parties. If exploited, an attacker could gain access to protected data, potentially compromising the confidentiality of industrial operations or system configurations.

Technical details

The Honeywell Control Network Module (CNM) is vulnerable to CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory). The vulnerability stems from the system placing sensitive information into directories that are not properly restricted. An attacker can exploit this over the network by probing system files to locate and extract protected data. While the attack vector is network-based, the complexity is rated as high, suggesting specific conditions or timing may be required to successfully intercept or locate the sensitive files. No authentication is required for the initial probing phase.

Affected products

  • Honeywell Control Network Module (CNM)

Timeline

  • 2026-05-21: disclosed: Initial publication of the CVE record.
  • 2026-05-21: advisory

References

Related threats