{"id":"CVE-2026-81861","title":"CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.","summary":"CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.","severity":"medium","cvss":5.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-522"],"vendor":"Schneider Electric","product":"SCADAPack 47x","affected":["scadapack_47x All versions","scadapack_47xi All versions","scadapack_47xd All versions","scadapack_470r All versions","scadapack_57x All versions","scadapack_3xx All versions","scadapack_32 All versions"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:30:42.730","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81861","references":[{"url":"https://download.se.com/files?p_Doc_Ref=SEVD-2026-251-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-251-03.pdf","label":"cybersecurity@se.com"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00384,"epssPercentile":0.32377,"exploits":{"github":1,"githubRepos":["https://github.com/abhinavagarwal07/scadapack-secure-lock-poc"],"checkedAt":"2026-09-24T07:53:19.551Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T19:13:51.210299Z"},"cvssSource":"cna","ingestedAt":"2026-09-14T00:35:28.534Z","slug":"CVE-2026-81861","body":"## Overview\n\nCWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}