← All briefs
Brief·2 sources17 Sept 2026

CVE-2026-15688 Exposes Mitsubishi Electric GX Works3 Authentication Bypass

vulnerability-disclosurecritical-infrastructuremanufacturinginitial-accessprivilege-escalation

Summary

CVE-2026-15688 is a high-severity authentication bypass vulnerability affecting Mitsubishi Electric GX Works3 and the bundled Motion Control Settings software, across all versions. Assigned a CVSS v3 score of 8.8, the flaw stems from an incorrect implementation of an authentication algorithm that allows a local attacker to authenticate successfully using an invalid block password by manipulating executable memory at runtime.

CISA published an ICS advisory on 17 September 2026, classifying the affected product under the Critical Manufacturing critical infrastructure sector. All deployed versions worldwide are confirmed affected. At the time of advisory publication, no public exploit code had been identified, though the nature of the vulnerability means that an attacker with local access to an engineering workstation running GX Works3 could view, tamper with, destroy, or delete control programs without legitimate credentials.

The vulnerability is particularly significant given GX Works3's role as a programmable logic controller (PLC) engineering environment used in industrial automation globally. Successful exploitation could give an attacker direct control over operational technology (OT) processes, with potential consequences ranging from production disruption to physical process manipulation.

Timeline

  1. 17 September 2026
    CISA Publishes ICS Advisory ICSA-26-260-02 for CVE-2026-15688
    CISA disclosed the authentication bypass vulnerability in Mitsubishi Electric GX Works3 and Motion Control Settings, assigning a CVSS v3 score of 8.8 and confirming all versions are affected worldwide.
  2. 17 September 2026
    VulDB Catalogues CVE-2026-15688 as Improper Authentication Flaw
    VulDB registered CVE-2026-15688, noting the vulnerability requires local access and that no public exploit exists at time of publication.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.

CVE-2026-15688 Exposes Mitsubishi Electric GX Works3 Authentication Bypass | Deltabridge