CVE-2026-79679
Received Received - Intake

Weak Credentials in B&R mapp Audit for mapp Services

Vulnerability report for CVE-2026-79679, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Asea Brown Boveri Ltd. (ABB)

Description

Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
b&r_industrial_automation_gmbh mapp_audit to 6.8.0 (exc)
b&r_industrial_automation_gmbh mapp_services to 6.8.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1391 The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the use of weak credentials in B&R Industrial Automation GmbH's mapp Audit software, which is part of their mapp Services. The issue stems from insufficient entropy in the authenticators used by mapp Audit, allowing attackers with network access to gain unauthorized entry to the OPC UA server component on affected devices.

Detection Guidance

To detect this vulnerability, check if your B&R mapp Services version is prior to 6.8.0. Verify the mapp Audit configuration and ensure the OPC UA server is not exposed to unauthorized network access. Use network scanning tools to identify devices running vulnerable versions.

Impact Analysis

An attacker could exploit this vulnerability to gain unauthorized access to the OPC UA server on affected devices. This may lead to data breaches, unauthorized control of industrial systems, or disruption of operations if the attacker manipulates system functions.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or sensitive data. Organizations may face legal penalties, reputational damage, and loss of trust due to potential data breaches or failure to protect regulated information.

Mitigation Strategies

Immediately update mapp Services to version 6.8.0 or later. Restrict network access to the OPC UA server component. Implement network isolation and physical security controls. Follow general cybersecurity best practices including regular software updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79679. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart