CVE-2026-27546 PUBLISHED

Authentication Bypass in _account_log

Assigner: CERTVDE
Reserved: 20.02.2026 Published: 16.09.2026 Updated: 16.09.2026

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Pepperl+Fuchs
Product ICE2-8IOL1-G65L-V1D
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE2-8IOL-G65L-V1D
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE2-8IOL-K45P-RJ45
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE2-8IOL-K45S-RJ45
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE3-8IOL1-G65L-V1D
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE3-8IOL-G65L-V1D
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE3-8IOL-G65L-V1D-Y
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE3-8IOL-K45P-RJ45
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Pepperl+Fuchs
Product ICE3-8IOL-K45S-RJ45
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Phoenix Contact
Product IOL MA8 PN DI8
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Phoenix Contact
Product IOL MA8 EIP DI8
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Carlo Gavazzi Automation
Product YL212CEI8M1IO
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Carlo Gavazzi Automation
Product YN115CEI8RPIO
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Carlo Gavazzi Automation
Product YL212CPN8M1IO
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)
Vendor Carlo Gavazzi Automation
Product YN115CPN8RPIO
Versions Default: unaffected
  • affected from 1.0.0 to 1.7.4 (excl.)

Credits

  • Gabriele Quagliarella from Nozomi Networks finder
  • Luca Borzacchiello from Nozomi Networks finder

References

Problem Types

  • CWE-288 Authentication Bypass Using an Alternate Path or Channel CWE