Critical Authentication Bypass in Mitsubishi Electric GX Works3 & Motion Control Settings (CVE‑2026‑15688) Threatens Industrial Control Programs
What It Is – A vulnerability (CVE‑2026‑15688) in Mitsubishi Electric GX Works3 and the bundled Motion Control Settings incorrectly implements the authentication algorithm. An attacker who can run the software locally can bypass password validation and modify executable code in memory.
Exploitability – CVSS v3 8.8 (High). The flaw is exploitable by a local user; no public exploit has been observed, but the attack path is straightforward.
Affected Products – Mitsubishi Electric GX Works3 (all versions) and Motion Control Settings (all versions) that ship with GX Works3.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous verification that authentication mechanisms remain intact across software updates.
- Provides a concrete control‑objective test for “identity and access management” – evidence of proper authentication is a key audit artifact.
- Highlights the importance of immutable logging of configuration changes to prove that control programs have not been tampered with, a requirement increasingly demanded by industrial buyers.
Recommended Actions
- Deploy Mitsubishi Electric’s security patch for CVE‑2026‑15688 immediately.
- Verify binary integrity of GX Works3 installations using hash‑based checksums.
- Enforce strict network segmentation so that engineering workstations cannot be reached from general corporate zones.
- Enable tamper‑evident logging of all changes to control‑program files and retain logs for audit.
- Document the remediation steps as evidence for control‑assurance reviews.
Source: CISA Advisory – ICSA‑26‑260‑02