Cyber & AI intelligence
Wasteland.
Briefs indexed2670
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-27546 2026-09-16

CVE-2026-27546: Critical Auth Bypass Lets Anyone Log In as Admin on IO-Link Masters

"A CVSS 9.8 authentication bypass in the `_account_log` function allows an unauthenticated remote attacker to log in as administrator on IO-Link master devices sold under the Pepperl+Fuchs, Phoenix Contact, and Carlo…"

A CVSS 9.8 authentication bypass in the _account_log function allows an unauthenticated remote attacker to log in as administrator on IO-Link master devices sold under the Pepperl+Fuchs, Phoenix Contact, and Carlo Gavazzi brands.

What Is It

CVE-2026-27546 is an improper authentication flaw (CWE-288, authentication bypass using an alternate path or channel) in the _account_log function of a shared IO-Link master firmware platform. Per the CERT@VDE advisory data, an unauthenticated remote attacker can exploit the bypass to log in as an admin, and this works even when accounts are properly configured, meaning correct credential hygiene does not mitigate it.

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8, CRITICAL. Network reachable, low complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

There is no meaningful barrier to exploitation here. Anything that can reach the device's management interface over the network can obtain administrative access. On an IO-Link master, admin access means control over the device's configuration and the industrial I/O it fronts; full read, write, and disruption capability against the process layer.

The vulnerability spans three separate vendors' product lines, which points to a shared OEM firmware base. Asset owners may be exposed through devices they do not associate with a single vendor advisory.

What's Vulnerable

All affected products are vulnerable in firmware versions 1.0.0 up to (but not including) 1.7.4:

Patch Status

The affected version ranges all terminate below 1.7.4, indicating firmware 1.7.4 and later are not affected. Consult the three linked CERT@VDE advisories for vendor-specific update guidance.

CVE-2026-27546 is not listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-16; readers can verify the current status directly against the catalog, linked below. Absent a KEV listing, there is no confirmation of active exploitation and no federally mandated remediation deadline. NVD status is "Received" as of publication on 2026-09-16, so the record may still be enriched.

Sources