CVE-2026-15953: Path Traversal During Project Archive Import
Published Sep 28, 2026
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600).
This issue affects Protection and control IED manager (PCM600): through 2.14.
Affected Software
1 affected component
ABB Protection and control IED manager (PCM600)<=2.14
Event History
Sep 28, 2026
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and conditions are required for exploitation?
The attack vector is local and requires low privileges. Exploitation also requires user interaction.
2
Which PCM600 versions are affected?
ABB Protection and control IED manager (PCM600) versions through 2.14 are affected.
3
What is the expected security impact?
The reported impact is limited to integrity; no confidentiality or availability impact is listed.