Skip to content

Security1 publisher2 min readPublished

Copy Fail gives a compromised Edgenius container root on ABB's bE100 gateway

CVE-2026-31431 escalates a locally authenticated user or a compromised container workload to root through the Linux kernel's algif_aead interface. ABB has fixed it in Edgenius 3.2.4.1 for the bE100 gateway.

The Watch · Security desk

Illustration accompanying Copy Fail gives a compromised Edgenius container root on ABB's bE100 gateway

What happened

  • ABB says CVE-2026-31431, called Copy Fail, lets a locally authenticated user or a compromised container workload gain root on affected systems, at which point the attacker has complete control of the machine.
  • The bug originates in the Linux kernel's cryptographic subsystem and affects kernels used by most major Linux distributions released since 2017.
  • ABB has corrected the problem in Edgenius 3.2.4.1 and recommends customers apply the update at earliest convenience.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Edgenius exists to host applications beside control systems, so one compromised hosted container is enough to own the gateway that collects data from those control systems.
  • decision Restricting ssh and cockpit access does nothing about a workload already running on the box, so operators who rely on that mitigation are choosing to accept the container path until 3.2.4.1 is installed.
  • constraint The local code execution requirement keeps this in the post-compromise escalation category, which is an argument for the next scheduled maintenance window and not for an emergency one.
  • contradiction The advisory lists 3.2.4.1 both in the affected line and as the corrected version, so anyone checking build numbers against it will need ABB's PSIRT advisory to confirm which side of the fix they are on.

The flaw is in the Linux kernel's algif_aead cryptographic algorithm interface. ABB's FAQ describes an incorrect in-place operation introduced where the source and destination data mappings were different, and says that could lead to unexpected behavior or data integrity issues during cryptographic operations, potentially affecting the reliability of encrypted communications [8]. CISA files it under CWE-669, incorrect resource transfer between spheres [9]. ABB says successful exploitation could let a local attacker gain administrative control of the system node, execute arbitrary code, or make the node unavailable [10].

Local code execution comes first [6]. On a default install, finding an account to log in with is not the easy part: ABB says no additional lower-privilege users are present on Edgenius installations, and its recommended mitigations are limiting access to ssh or cockpit [7]. That leaves the hosted applications. Edgenius connects to control systems, devices and equipment, collects and contextualizes operational data, and hosts applications that deliver real-time insights and AI-driven recommendations [11], and ABB's description of the bug covers a compromised container workload alongside a logged-in user [1]. ABB adds that shared, containerized or multi-tenant environments may increase the risk [6].

About nine years of distribution kernel releases fall inside the affected range [16]. ABB PSIRT reported the vulnerability to CISA, and the advisory addresses Edgenius on the Edgenius Gateway bE100 [13][3]. Other Linux-based OT appliances of the same vintage need their own vendors to say whether the kernel underneath them carries the same interface.

The advisory does not include a CVSS score, and it refers to public reports of the vulnerability without stating that exploitation has been observed [15]. CISA lists Edgenius deployments worldwide, across critical manufacturing, energy, water and wastewater, and chemical [12]. ABB's own security advisory for the fix is numbered 7PAA024620 [14].

What to watch

  • Whether other OT vendors shipping container-hosting edge appliances publish CVE-2026-31431 advisories of their own.
  • A public exploit for algif_aead would turn this into a standard next step after any container compromise on a Linux-based gateway.
  • ABB clarifying whether Edgenius 3.2.4.1 is affected, fixed, or both.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories