CVE-2026-8046: Incorrect Authorization in CODESYS Control
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8046?
CVE-2026-8046 has a severity score of 8.1, categorized as high risk.
How can I fix CVE-2026-8046?
To fix CVE-2026-8046, ensure that proper authorization checks are implemented when performing actions like deleting user accounts.
Who is affected by CVE-2026-8046?
CVE-2026-8046 affects users of CODESYS Control products that do not verify user authorization adequately.
What type of attack can CVE-2026-8046 facilitate?
CVE-2026-8046 allows low-privileged authenticated users to delete other user accounts, including those with higher privileges.
Is CVE-2026-8046 being actively exploited?
While there is no specific information related to active exploitation, the vulnerability poses a significant risk due to its authorization flaws.