highOther

ABB Ability Edgenius Linux Kernel Local Privilege Escalation (Copy Fail)

First seen Sep 19, 2026 · Updated Sep 19, 2026 · CVSS 7.8

icsotlinux-kernelprivilege-escalationcritical-infrastructureedge-computingcryptographic-flaw

ABB Ability Edgenius, an edge computing platform used in industrial control environments, contains a Linux kernel vulnerability (CVE-2026-31431, dubbed 'Copy Fail') that allows a locally authenticated user or compromised container workload to escalate privileges to root. The flaw resides in the kernel's algif_aead cryptographic interface and affects Linux kernels used broadly since 2017, though exploitation requires local access. ABB has released version 3.2.4.1 to remediate the issue.

Technical Analysis

CVE-2026-31431 is a CWE-669 (Incorrect Resource Transfer Between Spheres) flaw in the Linux kernel's algif_aead cryptographic algorithm interface, where mismatched source/destination memory mappings during in-place cryptographic operations lead to incorrect memory handling. A local attacker or compromised container workload can leverage this flaw to escalate from a standard user to root, granting full control of the affected node; CVSS 3.1 score is 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability affects ABB Ability Edgenius versions >=3.2.0.0 and <3.2.4.1 running on the Edgenius Gateway - bE100, deployed across Critical Manufacturing, Energy, Water/Wastewater, and Chemical sectors worldwide. Since Edgenius is explicitly marketed as an edge platform that 'hosts applications delivering real-time insights and AI-driven recommendations,' any AI agent or automation workload running as a container on a compromised Edgenius node could be leveraged as the initial local foothold to escalate to root, potentially compromising the entire industrial edge node and any AI/agent-driven decision pipelines running on it.

Affected Systems

ABB Ability Edgenius versions >=3.2.0.0 and <3.2.4.1 installed on ABB Ability Edgenius Gateway - bE100; underlying Linux kernels using the algif_aead cryptographic interface (kernels from most major distributions released since 2017).

Indicators of Compromise

  • No specific IOCs published; vulnerability is a kernel-level logic flaw rather than malware-based (no hashes, IPs, or domains associated with this advisory).

Remediation Steps

  1. 1

    Apply Vendor Patch

    Upgrade ABB Ability Edgenius to version 3.2.4.1 or later, which incorporates the corrected Linux kernel security update.

  2. 2

    Restrict Local/SSH Access

    Limit access to SSH or Cockpit management interfaces on Edgenius nodes; ensure no unnecessary lower-privilege user accounts exist on installations.

  3. 3

    Network Segmentation

    Isolate control system networks and Edgenius devices from business networks and the internet; place them behind firewalls.

  4. 4

    Secure Remote Access

    Use VPNs for any required remote access, keeping VPN software updated and hardened.

  5. 5

    Container Workload Hardening

    Audit and restrict privileges of container workloads running on Edgenius nodes, including any AI/automation agents, to reduce the risk of local exploitation leading to privilege escalation.

  6. 6

    Monitor and Report

    Monitor for anomalous local privilege escalation attempts and report suspected malicious activity to CISA and ABB PSIRT.

CVE / Advisory IDs

CVE-2026-31431

Industries Most Exposed

Critical ManufacturingEnergyWater and WastewaterChemical

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.