ZeroHour

CVE-2026-79679

moderate

Use of Weak Credentials in B&R Industrial Automation mapp Audit before 6.8.0

CVSS 4.0
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-79679 is a 'Use of Weak Credentials' flaw (CWE-1391) in the mapp Audit component of B&R Industrial Automation's mapp Services, affecting all versions before 6.8.0. The component is reachable over the network without privileges or user interaction (AV:N, PR:N, UI:N per the CVSS 4.0 vector), so an attacker with network access to an affected B&R controller can leverage the weak or default credentials it relies on, though the CVSS Attack Requirements metric (AT:P) indicates some deployment preconditions must be met. The vector shows no direct confidentiality, integrity, or availability impact on the vulnerable system itself, but high impact on subsequent systems (SC:H/SI:H), meaning the weak credentials can be used to compromise other systems or services connected to the controller. Affected users are operators of B&R (ABB) industrial controllers and machines built with mapp Services where mapp Audit is in use. There are no signs of exploitation so far: EPSS is 0.2% (10th percentile), the flaw is not in CISA KEV, and no public proof-of-concept is known.

What to do: Upgrade mapp Services/mapp Audit to version 6.8.0 or later. As interim mitigation, restrict network access to affected B&R controllers, rotate or replace any weak/default credentials used or managed through mapp Audit, and check for credential reuse that could enable lateral movement to connected systems. First confirm whether mapp Audit is actually enabled on deployed controllers before prioritizing patching.

Affected
B&R Industrial Automation GmbH (ABB) mapp Audit (used in mapp Services)all versions before 6.8.0
Estimated exposure
moderatetens of thousands of B&R controller/machine deployments (order-of-magnitude estimate; no public install counts for mapp Audit) — No public install counts or scan telemetry exist for mapp Audit; the estimate reflects B&R's (ABB's) large installed base of industrial controllers among machine builders, since mapp Services is a bundled B&R software framework, narrowed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.

Weakness
CWE-1391
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.