ics-otregulatorNewsThe Broadside2 min read

All GX Works3 Versions Face Authentication Bypass

Mitsubishi has workarounds but no permanent patch timeline for the CVSS 8.8 flaw that lets local attackers bypass GX Works3 block passwords and modify or destroy control programs.


TL;DR

CISA published an advisory for CVE-2026-15688, an authentication bypass affecting all versions of Mitsubishi Electric GX Works3 and Motion Control Settings. A local attacker who can execute the product can modify the executable in memory to bypass block passwords, gaining the ability to view, tamper with, destroy, or delete industrial control programs at CVSS 8.8. Mitsubishi has released workaround versions, 1.096A for GX Works3 and 1.070Y for Motion Control Settings, that require operators to set each project's security version to "2." No timeline for permanent patches has been provided.

Mitsubishi Electric's GX Works3 engineering software, deployed worldwide in critical manufacturing environments to program MELSEC PLCs, has an authentication bypass in every version shipped. That's the scope of CVE-2026-15688, which CISA republished from Mitsubishi's own advisory on September 17. A local attacker who can execute the product can modify the executable module in memory to authenticate with an invalid block password, then view, tamper with, destroy, or delete control programs. CVSS 3.1 puts it at 8.8; CVSS 4.0 scores it 9.2.

Mitsubishi's response is a pair of workaround versions: 1.096A for GX Works3 and 1.070Y for Motion Control Settings. Each requires operators to explicitly set project security versions to "2." This isn't a patch that closes the vulnerability; it's a configuration hardening that mitigates the attack surface. The company's advisory is silent on when a permanent fix will ship.

The authentication bypass lands in software with a dense vulnerability history. CISA's advisory archive shows GX Works3 has been the subject of at least three prior ICS advisories: ICSA-22-333-05 (cleartext storage, hard-coded passwords, hard-coded cryptographic keys, CVSS 9.1), ICSA-24-135-04 (Jungo WinDriver privilege escalation and DoS), and ICSA-20-212-04 (file permission issues enabling remote disclosure, tampering, and DoS). The Mitsubishi FA engineering ecosystem has accumulated dozens of CVEs spanning hard-coded credentials, insufficiently protected secrets, and authentication weaknesses. CVE-2026-15688 fits a pattern, not an aberration.

For the ICS operator, Monday means a choice. The workaround requires downloading new versions and reconfiguring project security settings, not a simple patch deployment. Mitsubishi's mitigation guidance also calls for LAN isolation, VPNs for remote access, antivirus on engineering workstations, and physical access restrictions. Operators who can't implement the workaround immediately should treat any workstation running GX Works3 or Motion Control Settings as a potential vector for control program compromise and restrict access accordingly. The absence of a permanent patch timeline means this interim posture isn't measured in days.


Published ·Deep Fathom

All GX Works3 Versions Face Authentication Bypass — The Broadside