1. Executive summary
CISA has republished Mitsubishi Electric advisory 2026-007 covering CVE-2026-15688, an incorrect implementation of an authentication algorithm (CWE-303) affecting all versions of GX Works3 and the bundled Motion Control Settings software. A local attacker who can execute the affected product can authenticate with an invalid block password and modify part of the executable module in memory, then view, tamper with, destroy or delete control programs. CVSS v3.1 is 8.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) and CVSS v4.0 is 9.2 CRITICAL (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H). No CISA-KEV exploitation state is recorded for this CVE. Direct risk to EMEA financial services is low: the affected products are PLC engineering tools deployed in critical manufacturing, not banking infrastructure. The exposure for financial institutions is confined to owned or contracted facilities, building management deployments and any OT estate where Mitsubishi PLCs are programmed with these tools.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The vulnerability is a vendor disclosure in industrial engineering software with no reported incident, no exploitation in the wild and no third-party service relationship specific to this flaw. Patching an engineering workstation on a client's own OT estate falls under general ICT risk management and does not trigger a distinctive obligation under the articles in scope.
3. Technical analysis & attack chain
CVE-2026-15688 is an authentication bypass in the block password mechanism of GX Works3 and Motion Control Settings. The confirmed attack chain is short because the vulnerability is local and single-step:
- The attacker obtains local code execution on a workstation running GX Works3 or Motion Control Settings, with local user privileges (PR:L in the v3.1 vector; no user interaction required).
- The attacker executes the affected product. During execution, the product's implementation of its block password authentication algorithm accepts an invalid password as valid.
- With authentication bypassed, the attacker modifies part of the executable module in memory.
- The attacker can then view, tamper with, destroy or delete control programs held in the project.
The scope change in the v3.1 vector (S:C) with high impacts across confidentiality, integrity and availability reflects that the compromised control programs govern PLC behaviour, so integrity loss in the engineering tool propagates to the controlled process. The v4.0 vector scores the changed-system integrity and availability impacts as high (SI:H/SA:H) while the vulnerable component's own availability impact is none (VA:N), consistent with a tool that itself keeps running while the programs it manages are altered.
Affected versions are all versions of both products: GX Works3 vers:all/ and Motion Control Settings (software packaged with GX Works3) vers:all/. There is no fixed version; the vendor supplies a workaround only. For GX Works3, install version 1.096A or later and set the security version for projects to "2". For Motion Control Settings, install version 1.070Y or later and set the security version for projects to "2". The security version setting is the operative control: Mitsubishi documents it in section 15.9 of the GX Works3 Operating Manual and section 12.5 of the Motion Control Setting Function Help, both under the heading "Preventing Illegal Access to/Falsification of Data (Security Version)".
The advisory does not describe the memory-modification technique in further technical detail, does not name the affected binary or component, and does not provide proof-of-concept code or a public exploit reference. No exploitation in the wild is reported. All technical detail in this section is single-sourced to the Mitsubishi Electric advisory as republished by CISA; the CISA page states it is a verbatim republication of Mitsubishi Electric 2026-007 from the vendor's CSAF advisory and that CISA takes no position on its editorial or technical accuracy.
4. Mitigation & containment
P1, within 24 hours: Identify every workstation in the estate running GX Works3 or Motion Control Settings, including engineering laptops used by maintenance contractors. Record the installed version and the current project security version setting. If any of these workstations sit outside a controlled OT LAN or permit remote login from untrusted networks, hosts or users, block that remote access now.
P2, within 72 hours: Upgrade GX Works3 to version 1.096A or later and Motion Control Settings to version 1.070Y or later, then set the security version for projects to "2" on every project handled by those installations. Both downloads are available from Mitsubishi Electric's software download portal; the vendor's own advisory at https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf carries the full procedure. Treat the security version setting as mandatory: upgrading the software without setting security version "2" leaves projects on the weaker scheme.
P3, within 7 days: Apply the vendor's environmental mitigations to each affected workstation: keep it inside a LAN with remote logins blocked from untrusted sources; place firewall or VPN controls in front of any internet-connected engineering machine and allow remote login only to trusted users; restrict physical access to the workstation and to the computers and network devices that can communicate with it; run antivirus on the machine; and train users not to open links or attachments from untrusted sources. Where engineering workstations are shared, review local account provisioning so that only engineers who need to modify control programs hold local accounts on them.
5. Indicators of compromise
No indicators of compromise available in the source material. The advisory describes a vulnerability and its remediation; it reports no exploitation, no malware and no observable artefacts.
6. Detection
Insufficient indicators to author detection rules. The source material contains no strings, file paths, registry keys, command lines or behavioural signatures associated with exploitation of CVE-2026-15688. The vendor advisory names product versions and manual sections, which are remediation references rather than threat artefacts and cannot support a detection rule.
7. Sources
- CISA, "Mitsubishi Electric GX Works3 and Motion Control Settings" (ICS-CERT advisory ICSA-26-260-02, republication of Mitsubishi Electric 2026-007), https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02, 2026-09-17
- Mitsubishi Electric, security advisory 2026-007, https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf, referenced by CISA ICSA-26-260-02
8. Adverse Trace position
We assess this as a high-severity vulnerability in the affected products on the vendor's own scoring (CVSS v3.1 8.8 HIGH, v4.0 9.2 CRITICAL) but with low direct impact for EMEA financial services clients, since GX Works3 and Motion Control Settings are PLC engineering tools for critical manufacturing rather than financial sector infrastructure. The local attack vector and the absence of any reported exploitation or CISA-KEV listing reduce urgency further; the practical risk concentrates in owned facilities, physical security estates and OT environments programmed with these tools. The entire technical picture is single-sourced to the Mitsubishi advisory republished by CISA, and the vendor offers a workaround rather than a patch, so clients should verify that the security version "2" setting is actually applied per project after upgrading, not assume the software upgrade alone closes the issue. We will monitor for a CISA-KEV addition, a proof-of-concept publication or any incident reporting involving these products, and will reissue this advisory if exploitation is observed.
Published via PulseTrace — Adverse Trace threat intelligence.