CVE-2026-0393

The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codesys:visualization:*:*:*:*:*:*:*:*

History

01 Jun 2026, 14:01

Type Values Removed Values Added
References () https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-07_vde-2026-052.jsonĀ - () https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-07_vde-2026-052.jsonĀ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Codesys
Codesys visualization
CPE cpe:2.3:a:codesys:visualization:*:*:*:*:*:*:*:*

21 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 12:16

Updated : 2026-06-01 14:01


NVD link : CVE-2026-0393

Mitre link : CVE-2026-0393

CVE.ORG link : CVE-2026-0393


JSON object : View

Products Affected

codesys

  • visualization
CWE
CWE-522

Insufficiently Protected Credentials