← back
CVE-2026-0393

CODESYS Visualization - Insufficiently Protected Credentials

CVSS 6.9 MEDIUMEPSS 0.2%CWE-522
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
21 May 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
CODESYS · Visualization

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →