Description
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
Published: 2026-05-26
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 07:45:00 +0000

Type Values Removed Values Added
Description The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
Title Incorrect Authorization in CODESYS Control
First Time appeared Codesys
Codesys codesys Control For Beaglebone Sl
Codesys codesys Control For Empc A Imx6 Sl
Codesys codesys Control For Iot2000 Sl
Codesys codesys Control For Linux Arm Sl
Codesys codesys Control For Linux Sl
Codesys codesys Control For Pfc100 Sl
Codesys codesys Control For Pfc200 Sl
Codesys codesys Control For Plcnext Sl
Codesys codesys Control For Raspberry Pi Sl
Codesys codesys Control For Wago Touch Panels 600 Sl
Codesys codesys Control Rte For Beckhoff Cx Sl
Codesys codesys Control Rte Sl
Codesys codesys Control Win Sl
Codesys codesys Hmi Sl
Codesys codesys Runtime Toolkit
Codesys codesys Virtual Control Sl
Weaknesses CWE-863
CPEs cpe:2.3:a:codesys:codesys_control_for_beaglebone_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_empc_a_imx6_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_iot2000_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_linux_arm_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_linux_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_pfc100_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_pfc200_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_plcnext_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_raspberry_pi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_for_wago_touch_panels_600_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_rte_for_beckhoff_cx_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_rte_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_control_win_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_hmi_sl:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_runtime_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:codesys:codesys_virtual_control_sl_:*:*:*:*:*:*:*:*
Vendors & Products Codesys
Codesys codesys Control For Beaglebone Sl
Codesys codesys Control For Empc A Imx6 Sl
Codesys codesys Control For Iot2000 Sl
Codesys codesys Control For Linux Arm Sl
Codesys codesys Control For Linux Sl
Codesys codesys Control For Pfc100 Sl
Codesys codesys Control For Pfc200 Sl
Codesys codesys Control For Plcnext Sl
Codesys codesys Control For Raspberry Pi Sl
Codesys codesys Control For Wago Touch Panels 600 Sl
Codesys codesys Control Rte For Beckhoff Cx Sl
Codesys codesys Control Rte Sl
Codesys codesys Control Win Sl
Codesys codesys Hmi Sl
Codesys codesys Runtime Toolkit
Codesys codesys Virtual Control Sl
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Codesys Codesys Control For Beaglebone Sl Codesys Control For Empc A Imx6 Sl Codesys Control For Iot2000 Sl Codesys Control For Linux Arm Sl Codesys Control For Linux Sl Codesys Control For Pfc100 Sl Codesys Control For Pfc200 Sl Codesys Control For Plcnext Sl Codesys Control For Raspberry Pi Sl Codesys Control For Wago Touch Panels 600 Sl Codesys Control Rte For Beckhoff Cx Sl Codesys Control Rte Sl Codesys Control Win Sl Codesys Hmi Sl Codesys Runtime Toolkit Codesys Virtual Control Sl
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-26T06:46:47.189Z

Reserved: 2026-05-06T17:10:12.759Z

Link: CVE-2026-8046

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses