Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Privilege Escalation & Path‑Traversal Vulnerabilities Disclosed in ABB PCM600 IED Manager (CVE‑2026‑15952, CVE‑2026‑15953)

ABB’s IED Manager PCM600 (≤ 2.14) contains two flaws that let a logged‑in user gain LocalSystem rights or overwrite arbitrary files. The issue highlights the need for strict access‑control controls and auditable remediation evidence for critical infrastructure operators.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

Privilege Escalation & Path‑Traversal in ABB Protection & Control IED Manager PCM600 (CVE‑2026‑15952, CVE‑2026‑15953)

What It Is – Two critical flaws were disclosed in ABB’s IED Manager PCM600 (versions ≤ 2.14). CVE‑2026‑15952 is an incorrect permission assignment that lets a standard user elevate to LocalSystem. CVE‑2026‑15953 is a path‑traversal flaw that can be used to overwrite arbitrary files.

Exploitability – Both vulnerabilities have a CVSS v3.1 base score of 6.4 (moderate). Exploits require a valid local user account; no public exploit code is known, but the attack surface is realistic for on‑site operators or compromised insider credentials.

Affected Products – ABB Protection and Control IED Manager PCM600, all releases up to version 2.14.

Why It Matters for Trust & Control Assurance

  • Access‑control hygiene – The privilege‑escalation flaw shows why strict separation of duties and least‑privilege assignments are essential control objectives.
  • Evidence of remediation – Demonstrating that the vulnerability is patched (or mitigated) provides concrete audit evidence for regulators and customers demanding continuous assurance.
  • Defensible incident response – Knowing the exact vector (local service running as LocalSystem) enables focused monitoring and rapid containment, reinforcing a trustworthy security posture.

Recommended Actions

  • Apply ABB’s latest firmware release (≥ 2.15) that resolves CVE‑2026‑15952 and CVE‑2026‑15953.
  • If immediate patching is not possible, implement the vendor‑provided workaround: restrict Scheduler Service execution to a dedicated, non‑privileged account and enforce file‑system ACLs that block unauthorized path traversal.
  • Review and tighten local user group memberships on all PCM600 hosts; enforce least‑privilege principles.
  • Enable logging of privileged service starts and file‑write events; forward logs to a centralized SIEM for continuous monitoring.
  • Capture remediation evidence (patch logs, configuration snapshots) for audit readiness.

Source: CISA Advisory – ICSA‑26‑274‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-03 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →