Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Authentication Bypass in Mitsubishi Electric GX Works3 & Motion Control Settings (CVE‑2026‑15688) Threatens Industrial Control Programs

CVE‑2026‑15688 lets a local attacker bypass password checks in Mitsubishi Electric GX Works3 and Motion Control Settings, enabling view, modification, or deletion of control programs. The flaw underscores the need for robust access‑control evidence and immutable logging for audit readiness.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Critical Authentication Bypass in Mitsubishi Electric GX Works3 & Motion Control Settings (CVE‑2026‑15688) Threatens Industrial Control Programs

What It Is – A vulnerability (CVE‑2026‑15688) in Mitsubishi Electric GX Works3 and the bundled Motion Control Settings incorrectly implements the authentication algorithm. An attacker who can run the software locally can bypass password validation and modify executable code in memory.

Exploitability – CVSS v3 8.8 (High). The flaw is exploitable by a local user; no public exploit has been observed, but the attack path is straightforward.

Affected Products – Mitsubishi Electric GX Works3 (all versions) and Motion Control Settings (all versions) that ship with GX Works3.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous verification that authentication mechanisms remain intact across software updates.
  • Provides a concrete control‑objective test for “identity and access management” – evidence of proper authentication is a key audit artifact.
  • Highlights the importance of immutable logging of configuration changes to prove that control programs have not been tampered with, a requirement increasingly demanded by industrial buyers.

Recommended Actions

  • Deploy Mitsubishi Electric’s security patch for CVE‑2026‑15688 immediately.
  • Verify binary integrity of GX Works3 installations using hash‑based checksums.
  • Enforce strict network segmentation so that engineering workstations cannot be reached from general corporate zones.
  • Enable tamper‑evident logging of all changes to control‑program files and retain logs for audit.
  • Document the remediation steps as evidence for control‑assurance reviews.

Source: CISA Advisory – ICSA‑26‑260‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →