CVE-2026-15688 PUBLISHED

Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting

Assigner: Mitsubishi
Reserved: 14.07.2026 Published: 17.09.2026 Updated: 17.09.2026

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H
CVSS Score: 9.2

Product Status

Vendor Mitsubishi Electric Corporation
Product GX Works3
Versions Default: unaffected
  • Version All versions is affected
Vendor Mitsubishi Electric Corporation
Product Motion Control Setting
Versions Default: unaffected
  • Version All versions is affected

References

Problem Types

  • CWE-303 Incorrect Implementation of Authentication Algorithm CWE

Impacts

  • Password Authentication Bypass