Critical Privilege Escalation via Cookie Manipulation in Weintek cMT3092X HMI (CVE‑2026‑60134)
What It Is — A newly disclosed vulnerability (CVE‑2026‑60134) in the Weintek cMT3092X Human‑Machine Interface (HMI) allows a non‑privileged user to tamper with authentication cookies, elevate privileges, and view other users’ credentials.
Exploitability — The flaw is rated CVSS v3 8.8 (High). Public proof‑of‑concept code exists, and exploitation does not require prior authentication beyond a standard user account.
Affected Products — Weintek cMT3092X devices running firmware < 20210218 or EasyWeb < v2.1.20. The product is deployed worldwide in critical manufacturing environments.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls (CC6.1, CC6.2) – The issue highlights gaps in authentication integrity and privilege‑separation, which auditors scrutinize for evidence of robust access‑control policies.
- Continuous Monitoring – Detecting unauthorized cookie changes requires real‑time logging and alerting; maintaining this evidence is essential for a defensible SOC 2 audit.
- Audit Trail Integrity – If credentials can be harvested, logs may be tampered with, undermining the reliability of audit artifacts that demonstrate control effectiveness.
Recommended Actions
- Apply the vendor‑supplied patch cmt_typeB_20260316_007.patch (EasyWeb 2.3.17‑typeb) immediately.
- Verify that all HMI devices run firmware ≥ 20210218 and EasyWeb ≥ v2.1.20.
- Conduct a control‑mapping exercise to align cookie handling with SOC 2 CC6.1 requirements and capture the patch deployment as audit evidence.
- Enable immutable logging of authentication events and monitor for anomalous privilege changes.
- Update security policies to require integrity‑checked cookies and periodic credential rotation.
Source: CISA Advisory – ICSA‑26‑204‑03