CVE-2026-75813
—Unauthenticated Authorization Bypass in ICS Device Configuration Endpoints
CVE-2026-75813 is a missing-authorization vulnerability (CWE-862) in certain configuration endpoints of an industrial control system (ICS) device, assigned by CISA ICS-CERT, in which server-side authorization checks are absent and unauthorized users can reach sensitive device settings. Because the published CVSS 4.0 vector shows a network attack vector, low attack complexity, and no privileges or user interaction required, a remote, unauthenticated attacker can trigger the flaw simply by sending requests to the affected configuration endpoints, though the advisory's phrasing that endpoints may lack checks suggests exposure can depend on device configuration. An attacker gains the ability to access or modify sensitive device settings; the vector scores a high integrity impact (VI:H) with no confidentiality or availability impact, and the description warns this could result in full compromise of device functionality. Affected parties are operators of the affected device, but the data available here does not name the vendor, product, or version range, so defenders must consult the CISA ICS-CERT advisory to determine whether their deployments are affected. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3 percent probability of exploitation within 30 days (17th percentile).
What to do: Identify whether your environment contains the affected device using the CISA ICS-CERT advisory for CVE-2026-75813 and apply the vendor's patched firmware as soon as affected versions are confirmed. Until patching, restrict access to the device's configuration and management endpoints to trusted management networks (firewall rules, ACLs, VPN) and check whether any such endpoints are reachable from the internet or from untrusted networks. Review current device configuration for unauthorized changes and monitor for unexpected settings modifications.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.