CVE-2026-81855: Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
Published Sep 15, 2026
·Updated
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
Affected Software
1 affected component
Wärtsilä FOS-Onboard
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure Wärtsilä FOS-Onboard is installed exactly as recommended, as Wärtsilä states the vulnerability is not exploitable when installed as recommended.
Event History
Sep 15, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates that the vulnerability is network-accessible, requires no privileges or user interaction, and has low attack complexity.
2
What security impact is indicated?
The CVSS vector rates confidentiality and integrity impact as high, while availability impact is rated as none. The vulnerability has a critical severity score of 9.1.