CVE-2026-0393
Analyzed
Analyzed - Analysis Complete
Hard-Coded Credentials in Visualization Software
Publication date: 2026-05-21
Last updated on: 2026-06-01
Assigner: CERT VDE
Description
Description
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codesys | visualization | From 1.0.0.0 (inc) to 4.10.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |