Status: UPDATED | Advisory ID: CVE-2026-22619
| CVE | CVE-2026-22619 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Eaton Intelligent Power Protector |
| Classified as | CWE-427 (Uncontrolled Search Path Element) |
| Exploitation prediction (EPSS) | 0.32% probability of exploitation in the next 30 days (23% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Eaton | Intelligent Power Protector |
| Subsystems | General OT |
| Sectors | Multiple |
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.
Monitor Eaton's web page for any future patch releases. See vendor advisory link below.