← All Advisories

CVE-2026-22620

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-22620

Key Details

CVECVE-2026-22620
CVSS Score / Version8.6 (High) / CVSS v3.1
Updated2026-07-31
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is low; availability impact is high.
Affected productsEaton PADM
Classified asCWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
EatonPADM
SubsystemsGeneral OT
SectorsMultiple

What to Know

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.

What to Do

Monitor Eaton's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-22620
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-22620