Junglewise Threat Intelligence

CVE-2026-79679: B&R mapp Audit weak credentials in mapp Services

CVE-2026-79679 · Severity: high · CVSS 8.7 · Published 2026-09-03

Executive brief

mapp Audit is a component of B&R's mapp Services platform, used for audit logging and security monitoring in industrial automation environments. A weak credentials vulnerability allows attackers to gain unauthorized access to the audit system, potentially compromising the integrity of security logs and enabling tampering with evidence of malicious activity.

Technical details

The vulnerability involves the use of weak or hardcoded credentials in mapp Audit, a security-critical component of mapp Services. This allows unauthenticated or weakly-authenticated attackers to access the audit logging system, potentially from the network if the component is exposed. An attacker exploiting this flaw can read, modify, or delete audit logs, destroying evidence of security breaches and potentially covering tracks of other attacks. Versions before 6.8.0 are affected; updates should be applied to resolve the issue.

Affected products

  • B&R Industrial Automation GmbH mapp Audit before 6.8.0

Timeline

  • 2026-09-03: disclosed
  • other: Reported exploited in wild: false

References