← All Advisories

CVE-2026-0647

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-0647

Key Details

CVECVE-2026-0647
CVSS Score / Version8.8 (High) / CVSS v4.0
Updated2026-06-17
Affected productsRockwell Automation FLEX I/O EtherNet/IP Adapters
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Rockwell AutomationFLEX I/O EtherNet/IP Adapters
SubsystemsGeneral OT
SectorsMultiple

What to Know

An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the device’s embedded web server’s availability. (NVD)

What to Do

Monitor Rockwell Automation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0647
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0647