The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
References
| Link | Resource |
|---|---|
| https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-07_vde-2026-052.json | Vendor Advisory |
Configurations
History
01 Jun 2026, 14:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-07_vde-2026-052.jsonĀ - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Codesys
Codesys visualization |
|
| CPE | cpe:2.3:a:codesys:visualization:*:*:*:*:*:*:*:* |
21 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-21 12:16
Updated : 2026-06-01 14:01
NVD link : CVE-2026-0393
Mitre link : CVE-2026-0393
CVE.ORG link : CVE-2026-0393
JSON object : View
Products Affected
codesys
- visualization
CWE
CWE-522
Insufficiently Protected Credentials
