Panduit IntraVUE: Critical OT Bypass and Credential Exposure Flaws Disclosed Together
Three vulnerabilities in Panduit IntraVUE, including a critical OT bypass flaw, were disclosed on July 23, 2026, affecting versions 3.2.1a14 and prior.

Key findings
- Three vulnerabilities disclosed for Panduit IntraVUE on July 23, 2026.
- Critical vulnerability (CVE-2026-42933) allows bypassing OT segmentation via unintended proxy.
- High-severity flaw (CVE-2026-40430) exposes cleartext credentials through the API.
- Medium-severity vulnerability (CVE-2026-50044) involves inadequate encryption strength for credentials.
- Affects IntraVUE versions 3.2.1a14 and prior.
- Exploitation could allow manipulation of industrial control devices.
On July 23, 2026, a batch of three vulnerabilities was disclosed for Panduit IntraVUE, a product used in critical infrastructure sectors including manufacturing, energy, and water. These vulnerabilities, detailed in a CISA ICS Advisory (ICSA-26-204-04), could allow an attacker with IT network access to manipulate industrial control devices without physical access or specialized knowledge. The affected versions are IntraVUE 3.2.1a14 and prior.
One critical vulnerability, CVE-2026-42933, involves an unintended proxy or intermediary. This flaw could allow an attacker to leverage an active proxy to bypass Operational Technology (OT) segmentation, a significant concern for industrial control systems.
Additionally, a high-severity vulnerability, CVE-2026-40430, relates to the plaintext storage of passwords. This could expose cleartext credentials through the API, providing attackers with direct access to sensitive information.
A medium-severity vulnerability, CVE-2026-50044, stems from inadequate encryption strength. This could enable an attacker to steal administrator credentials through weak hashing or a pass-the-hash attack.
Successful exploitation of these vulnerabilities could allow an attacker to manipulate industrial control devices. The CISA advisory notes that these issues affect versions of Panduit IntraVUE up to and including 3.2.1a14.
This coordinated disclosure highlights potential risks for organizations relying on Panduit IntraVUE for their industrial control systems. Users are advised to update to patched versions as soon as possible to mitigate these risks. The full impact could be significant, potentially allowing unauthorized control over critical infrastructure.