← All Advisories

Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.8

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-22619

Key Details

CVECVE-2026-22619
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsEaton Intelligent Power Protector
Classified asCWE-427 (Uncontrolled Search Path Element)
Exploitation prediction (EPSS)0.32% probability of exploitation in the next 30 days (23% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
EatonIntelligent Power Protector
SubsystemsGeneral OT
SectorsMultiple

What to Know

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.

What to Do

Monitor Eaton's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-22619
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-22619
Vendor advisoryhttps://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1025.pdf