ZeroHour
CISA Advisoriespublished ()ingested CISA
Part of a story covered by 2 sources: “CISA Issues Two Mitsubishi Electric Advisories: CC-Link IE TSN Packet Tampering and GX Works3 Block Password Bypass (CVE-2026-15688)” — merged summary and timeline →

Mitsubishi Electric GX Works3 and Motion Control Settings

mediumAdvisoryimportance 35CVE-2026-15688
AI summary · glm-5.3-flash

CISA warns CVE-2026-15688 lets a local attacker bypass block password authentication in Mitsubishi Electric GX Works3 and tamper with control programs.

CISA republished Mitsubishi Electric advisory 2026-007 describing CVE-2026-15688, an incorrect implementation of the authentication algorithm (CWE-303) in GX Works3 and the bundled Motion Control Settings, affecting all versions. A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs. CVSS v3.1 base score is 8.8 (v4.0: 9.2), and CISA recommends isolating control system networks and minimizing internet exposure.

  • CVE-2026-15688 is a CWE-303 authentication algorithm flaw rated 8.8 (CVSS v3.1) and 9.2 (v4.0)
  • Local attacker can bypass invalid block password checks and modify executable modules in memory
  • All GX Works3 versions and packaged Motion Control Settings are affected
  • Attackers can view, tamper with, destroy, or delete PLC control programs
  • CISA urges isolating control networks and restricting internet exposure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15688
Block password bypass in Mitsubishi Electric GX Works3 and Motion Control Setting

Mitsubishi Electric's GX Works3 and Motion Control Setting engineering software implement the block password feature incorrectly (CWE-303), so authentication succeeds even with an invalid password. A local attacker with low privileges who can execute the affected software can modify part of the executable module in memory to bypass the password check. Once bypassed, the attacker can view, tamper with, destroy, or delete PLC control programs that the password was meant to protect. Any organization running the affected software on engineering workstations with access to MELSEC PLC environments is affected, since the attack requires only local access to the workstation. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA KEV.

Do: Inventory engineering workstations running GX Works3 and Motion Control Setting and upgrade to the fixed versions listed in Mitsubishi Electric's advisory for CVE-2026-15688. Until patched, restrict local logon and software execution on OT engineering workstations and treat the block password as change control rather than a security boundary. Audit control programs for unauthorized modifications and monitor for processes tampering with the GX Works3 executable in memory.

9.2
  • Mitsubishi Electric GX Works3
  • Mitsubishi Electric Motion Control Setting
large≈100,000+ engineering workstation installs worldwide (order of magnitude 10^5)
Full article607 words · extracted from cisa.gov · click to collapse

View CSAF

Summary

Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.

The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected:

  • Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)
  • Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3) vers:all/* (CVE-2026-15688)
CVSS Vendor Equipment Vulnerabilities
v3 8.8 Mitsubishi Electric Mitsubishi Electric GX Works3 and Motion Control Settings Incorrect Implementation of Authentication Algorithm

Background

  • Critical Infrastructure Sectors: Critical Manufacturing
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: Japan

Vulnerabilities

Expand All +

CVE-2026-15688

Incorrect Implementation of Authentication Algorithm (CWE-303) vulnerability in the affected products allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.

View CVE Details


Affected Products

Mitsubishi Electric GX Works3 and Motion Control Settings

Vendor:
Mitsubishi Electric

Product Version:
Mitsubishi Electric GX Works3: vers:all/*, Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3): vers:all/*

Product Status:
known_affected

Relevant CWE: CWE-303 Incorrect Implementation of Authentication Algorithm


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
4.0 9.2 CRITICAL CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H

Acknowledgments

  • Mayeul Fargier, Erwan Cordier, Noé Flatreaud reported this vulnerability to Mitsubishi Electric.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.

  • Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


Advisory Conversion Disclaimer

This ICSA is a verbatim republication of Mitsubishi Electric 2026-007 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.

Revision History

  • Initial Release Date: 2026-09-17
Date Revision Summary
2026-09-17 1 Initial Publication
2026-09-17 2 Initial CISA Republication of Mitsubishi Electric 2026-007 advisory

Legal Notice and Terms of Use

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02