Skip to content
Rota Nacional

Cyber ·

ABB PCM600 flaws may raise privileges and write outside a directory

A CISA advisory published on October 1, 2026 describes two vulnerabilities in ABB PCM600, used in the energy sector: one in Scheduler Service and another in project-file extraction. It reports risks of privilege escalation and writing outside the intended location.

The CISA advisory, published on October 1, 2026, concerns ABB Protection and Control IED Manager PCM600, a product associated with energy installations in many countries. It reports two flaws: improper permissions in Scheduler Service (CVE-2026-15952) and insufficient path validation when extracting project files (CVE-2026-15953). The supplied material does not specify affected versions.

For the first flaw, the service runs as LocalSystem, while standard PCM600 users receive permissions through membership in a local group. According to the advisory, an attacker with local access and valid credentials could escalate privileges and take control of the host. CVE-2026-15952 has a CVSS 3.1 score of 6.4 (medium) and a CVSS 4.0 score of 7.1 (high).

The second flaw could allow project-file extraction to write files outside the intended directory. To reduce the first flaw’s risk, ABB recommends configuring the ABBPCMSchedulerService instance for the installed version to use the same Windows account as PCM600, with the “Log on as a service” privilege. The advisory notes this is a mitigation, not a fix for the underlying vulnerability.

ABB also recommends using that same account for Scheduler when IED authentication is enabled. The PCM600 “Always trust IED security certificates” option should be enabled only in a secure, trusted environment. Before making changes, check the original CISA advisory and ABB advisories 2NGA003170 and 2NGA003179; confirm the product, installation, and guidance with the responsible team. The source text is an automatic translation and ends mid-entry, so verify details and updates in the original publications.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free