Junglewise Threat Intelligence

CVE-2026-6900: B&R Industrial Automation APROL improper certificate validation

CVE-2026-6900 · Severity: high · CVSS 7.4 · Published 2026-07-06

Vendors: B&R Industrial Automation.

Executive brief

B&R APROL, a process control system used in industrial automation, contains a security flaw in how it verifies digital certificates. This vulnerability could allow an attacker to intercept or modify sensitive data transmitted between systems by masquerading as a trusted entity. If exploited, this could lead to the unauthorized disclosure of operational data or the manipulation of system commands, potentially impacting industrial processes.

Technical details

A vulnerability classified as Improper Certificate Validation (CWE-295) exists in B&R Industrial Automation GmbH APROL versions prior to R 4.4-01P5. The software fails to adequately validate the authenticity of digital certificates during secure communications. An unauthenticated remote attacker could exploit this by performing a man-in-the-middle (MitM) attack to intercept, decrypt, or alter encrypted traffic between the APROL system and other endpoints. While the attack requires a specific network position (High Attack Complexity), a successful exploit results in high impacts to confidentiality and integrity. Users are advised to upgrade to version R 4.4-01P5 or later.

Affected products

  • B&R Industrial Automation GmbH APROL before R 4.4-01P5

Timeline

  • 2026-07-06: advisory: Initial advisory published by ABB/B&R Industrial Automation
  • 2026-07-06: disclosed: CVE-2026-6900 published to NVD

References

Related threats