ZeroHour

CVE-2026-15688

large

Block password bypass in Mitsubishi Electric GX Works3 and Motion Control Setting

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

Mitsubishi Electric's GX Works3 and Motion Control Setting engineering software implement the block password feature incorrectly (CWE-303), so authentication succeeds even with an invalid password. A local attacker with low privileges who can execute the affected software can modify part of the executable module in memory to bypass the password check. Once bypassed, the attacker can view, tamper with, destroy, or delete PLC control programs that the password was meant to protect. Any organization running the affected software on engineering workstations with access to MELSEC PLC environments is affected, since the attack requires only local access to the workstation. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA KEV.

What to do: Inventory engineering workstations running GX Works3 and Motion Control Setting and upgrade to the fixed versions listed in Mitsubishi Electric's advisory for CVE-2026-15688. Until patched, restrict local logon and software execution on OT engineering workstations and treat the block password as change control rather than a security boundary. Audit control programs for unauthorized modifications and monitor for processes tampering with the GX Works3 executable in memory.

Affected
Mitsubishi Electric GX Works3
Mitsubishi Electric Motion Control Setting
Estimated exposure
large≈100,000+ engineering workstation installs worldwide (order of magnitude 10^5) — Mitsubishi Electric is a top-tier global PLC vendor and GX Works3 is its standard engineering tool for MELSEC iQ-R/iQ-F PLCs, so seat installations plausibly reach six figures across industrial sites, though no public install counts exist…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.

Weakness
CWE-303
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Mitsubishi Electric GX Works3 and Motion Control Settings

CISA warns CVE-2026-15688 lets a local attacker bypass block password authentication in Mitsubishi Electric GX Works3 and tamper with control programs.

CISA republished Mitsubishi Electric advisory 2026-007 describing CVE-2026-15688, an incorrect implementation of the authentication algorithm (CWE-303) in GX Works3 and the bundled Motion Control Settings, affecting all versions. A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs. CVSS v3.1 base score is 8.8 (v4.0: 9.2), and CISA recommends isolating control system networks and minimizing internet exposure.

CISA Advisories · 1d agoAdvisoryCVE-2026-15688