Skip to content
Auto-CTI
Back to today
NEW HIGH A3

CVE-2026-3869: Incorrect Implementation of Authentication Algorithm in PLC

A NVD · · CVE-2026-3869

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

The vulnerability enables authentication bypass in PLC systems through incorrect implementation of authentication algorithms, which is particularly critical for legacy or lower application levels.

Description

CVE-2026-3869 describes an authentication implementation vulnerability in programmable logic controllers (PLCs). The vulnerability is caused by incorrect implementation of an authentication algorithm (CWE-303) and could allow an attacker to compromise the confidentiality, integrity, and availability of the PLC system. Exploitation requires that an application project with a lower application level is running on the PLC. The vulnerability has been registered in the NVD; active exploitation status is not fully documented.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC