ABB Ability Edgenius Linux Kernel Local Privilege Escalation (Copy Fail)
First seen Sep 19, 2026 · Updated Sep 19, 2026 · CVSS 7.8
ABB Ability Edgenius, an edge computing platform used in industrial control environments, contains a Linux kernel vulnerability (CVE-2026-31431, dubbed 'Copy Fail') that allows a locally authenticated user or compromised container workload to escalate privileges to root. The flaw resides in the kernel's algif_aead cryptographic interface and affects Linux kernels used broadly since 2017, though exploitation requires local access. ABB has released version 3.2.4.1 to remediate the issue.
Technical Analysis
CVE-2026-31431 is a CWE-669 (Incorrect Resource Transfer Between Spheres) flaw in the Linux kernel's algif_aead cryptographic algorithm interface, where mismatched source/destination memory mappings during in-place cryptographic operations lead to incorrect memory handling. A local attacker or compromised container workload can leverage this flaw to escalate from a standard user to root, granting full control of the affected node; CVSS 3.1 score is 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability affects ABB Ability Edgenius versions >=3.2.0.0 and <3.2.4.1 running on the Edgenius Gateway - bE100, deployed across Critical Manufacturing, Energy, Water/Wastewater, and Chemical sectors worldwide. Since Edgenius is explicitly marketed as an edge platform that 'hosts applications delivering real-time insights and AI-driven recommendations,' any AI agent or automation workload running as a container on a compromised Edgenius node could be leveraged as the initial local foothold to escalate to root, potentially compromising the entire industrial edge node and any AI/agent-driven decision pipelines running on it.
Affected Systems
ABB Ability Edgenius versions >=3.2.0.0 and <3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100; underlying Linux kernels using the algif_aead cryptographic interface (kernels from most major distributions released since 2017).
Indicators of Compromise
- No specific IOCs published; vulnerability is a kernel-level logic flaw rather than malware-based (no hashes, IPs, or domains associated with this advisory).
Remediation Steps
- 1
Apply Vendor Patch
Upgrade ABB Ability Edgenius to version 3.2.4.1 or later, which incorporates the corrected Linux kernel security update.
- 2
Restrict Local/SSH Access
Limit access to SSH or Cockpit management interfaces on Edgenius nodes; ensure no unnecessary lower-privilege user accounts exist on installations.
- 3
Network Segmentation
Isolate control system networks and Edgenius devices from business networks and the internet; place them behind firewalls.
- 4
Secure Remote Access
Use VPNs for any required remote access, keeping VPN software updated and hardened.
- 5
Container Workload Hardening
Audit and restrict privileges of container workloads running on Edgenius nodes, including any AI/automation agents, to reduce the risk of local exploitation leading to privilege escalation.
- 6
Monitor and Report
Monitor for anomalous local privilege escalation attempts and report suspected malicious activity to CISA and ABB PSIRT.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.