CISA Warns of Authentication Bypass Vulnerability in Mitsubishi Electric GX Works3
A critical vulnerability in Mitsubishi Electric's GX Works3 and Motion Control Settings software allows local attackers to bypass authentication and tamper with control programs.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability, identified as CVE-2026-15688, affecting Mitsubishi Electric's GX Works3 and its bundled Motion Control Settings software. This flaw, classified as an "Incorrect Implementation of Authentication Algorithm" (CWE-303), poses a significant risk to industrial control systems globally.
A local attacker with even invalid credentials can exploit this vulnerability. By executing the affected product and manipulating executable modules in memory, an attacker can gain unauthorized access. This access allows for the viewing, tampering, destruction, or deletion of critical control programs, potentially disrupting manufacturing operations and other industrial processes.
The vulnerability affects all versions of GX Works3 and the Motion Control Settings software that is packaged with it. The CVSS v3.1 base score for this vulnerability is a high 8.8, indicating a critical severity. The CVSS v4.0 score is even higher at 9.2, underscoring the potential impact.
Mitsubishi Electric has provided specific workarounds and recommended updates. For GX Works3 users, updating to version 1.096A or later and setting the security version for projects to "2" is advised. Similarly, Motion Control Settings users should update to version 1.070Y or later and apply the same security version setting. Detailed instructions can be found in the respective operating manuals and a dedicated Mitsubishi Electric security advisory.
Beyond software updates, Mitsubishi Electric also recommends several mitigation strategies to minimize exploitation risk. These include restricting network access to computers running the affected products, blocking remote logins from untrusted sources, and employing firewalls and VPNs for any necessary remote access. Furthermore, users are advised to maintain up-to-date antivirus software and restrict physical access to control system hardware.
CISA echoes these recommendations, urging users to minimize network exposure for all control system devices, ensure they are not accessible from the internet, and isolate control system networks behind firewalls. When remote access is necessary, secure methods like VPNs should be utilized, with the caveat that VPNs themselves must be kept updated and secured.
The vulnerability was reported to Mitsubishi Electric by researchers Mayeul Fargier, Erwan Cordier, and Noé Flatreaud. This incident highlights the ongoing challenges in securing operational technology (OT) environments, where vulnerabilities in widely used industrial software can have far-reaching consequences for critical infrastructure.
Organizations utilizing Mitsubishi Electric's GX Works3 and Motion Control Settings software are strongly encouraged to review the CISA alert and implement the recommended updates and security measures promptly to protect their systems from potential compromise.