highOther

Mitsubishi Electric GX Works3 and Motion Control Settings Authentication Bypass (CVE-2026-15688)

First seen Sep 18, 2026 · Updated Sep 18, 2026 · CVSS 8.8

ICSSCADAauthentication-bypassindustrial-control-systemscritical-manufacturingMitsubishi-Electriclocal-privilege-escalation

A vulnerability in Mitsubishi Electric GX Works3 and Motion Control Settings allows a local attacker to bypass block password authentication and modify the executable module in memory. This enables an attacker to view, tamper with, destroy, or delete PLC control programs, posing a significant risk to industrial engineering workstations in critical manufacturing environments.

Technical Analysis

CVE-2026-15688 is classified as CWE-303 (Incorrect Implementation of Authentication Algorithm), allowing a local attacker to successfully authenticate with an invalid block password by executing the affected product and patching part of the executable module in memory. This grants unauthorized access to view, tamper with, destroy, or delete control programs used to configure Mitsubishi PLCs and motion controllers. The vulnerability carries a CVSS v3.1 score of 8.8 (High) and a CVSS v4.0 score of 9.2 (Critical), reflecting local attack vector with low complexity and no user interaction required beyond low privileges. This is an OT/ICS engineering software vulnerability with no direct AI agent tooling involvement, though organizations running AI-driven industrial monitoring or agentic automation on engineering workstations sharing this software should ensure those hosts are isolated, as compromise of the engineering workstation could indirectly expose any credentials or API keys used by agent-based OT monitoring tools running on the same machine.

Affected Systems

Mitsubishi Electric GX Works3 (all versions prior to 1.096A); Mitsubishi Electric Motion Control Settings software packaged with GX Works3 (all versions prior to 1.070Y)

Indicators of Compromise

  • No specific IOCs published; this is a design-level vulnerability requiring local access rather than a known exploited campaign with file hashes, IPs, or domains.

Remediation Steps

  1. 1

    Update GX Works3

    Download and install GX Works3 version 1.096A or later from Mitsubishi Electric's official download portal, then set the security version for projects to '2'.

  2. 2

    Update Motion Control Settings

    Download and install Motion Control Settings version 1.070Y or later, then set the security version for projects to '2' as described in the Motion Control Setting Function Help documentation.

  3. 3

    Restrict Network Exposure

    Keep engineering workstations running affected software on isolated LANs, block remote logins from untrusted networks, and ensure these systems are never directly accessible from the internet.

  4. 4

    Implement Firewall/VPN Controls

    Use firewalls and VPNs to control remote access, only allowing trusted users to connect, and keep VPN software updated.

  5. 5

    Endpoint Hardening

    Install antivirus software, restrict physical access to workstations and connected network devices, and train users to avoid clicking untrusted links or opening suspicious attachments.

  6. 6

    Network Segmentation

    Place ICS/OT networks behind firewalls, segmented from business/IT networks, following defense-in-depth best practices recommended by CISA.

CVE / Advisory IDs

CVE-2026-15688

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsEnergyUtilities

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.