← All Advisories

The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-27546

Key Details

CVECVE-2026-27546
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-16
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-288 (Authentication Bypass Using an Alternate Path or Channel)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Pepperl+FuchsICE2-8IOL-K45P-RJ45
Pepperl+FuchsICE2-8IOL1-G65L-V1D
Pepperl+FuchsICE2-8IOL-G65L-V1D
Pepperl+FuchsICE2-8IOL-K45S-RJ45
Pepperl+FuchsICE3-8IOL1-G65L-V1D
Pepperl+FuchsICE3-8IOL-G65L-V1D
Pepperl+FuchsICE3-8IOL-G65L-V1D-Y
Pepperl+FuchsICE3-8IOL-K45P-RJ45
Pepperl+FuchsICE3-8IOL-K45S-RJ45
Phoenix ContactIOL MA8 PN DI8
Phoenix ContactIOL MA8 EIP DI8
Carlo Gavazzi AutomationYL212CEI8M1IO
Carlo Gavazzi AutomationYN115CEI8RPIO
Carlo Gavazzi AutomationYL212CPN8M1IO
Carlo Gavazzi AutomationYN115CPN8RPIO
SubsystemsGeneral OT
SectorsMultiple

What to Know

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

What to Do

Monitor Pepperl+Fuchs, Phoenix Contact, and Carlo Gavazzi Automation's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-27546
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-27546