Security1 publisher2 min readPublished
ABB's PCM600 Scheduler Service gives standard users a route to LocalSystem control
ABB's PCM600 IED manager, versions 2.14 and earlier, lets a standard local user take control of the host through a Scheduler Service running as LocalSystem. ABB's remedy is a workaround it says reduces the risk without correcting the underlying flaw.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Standard PCM600 users hold permissions on the Scheduler Service through membership in the local Users group, a flaw CISA classes as CWE-732.
- A second flaw lets PCM600 write files outside the intended directory when it extracts a project archive, because archive entry paths are not properly validated.
- ABB tells operators to reconfigure the ABBPCMSchedulerService to log on as the same Windows account that runs the PCM600 application.
- CISA lists the affected sector as energy and the product's deployment as worldwide, from Switzerland-headquartered ABB.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any valid standard login on a PCM600 machine, including one an intruder has obtained, is enough to reach full control of that host, so the flaw's reach is set by who can log in locally.
- decision Operators now pick the account the Scheduler Service runs as, and that choice sets what a successful abuse of the service yields in place of LocalSystem.
- constraint The advisory offers no control aimed at archive extraction itself, so any project archive a PCM600 user unpacks stays a route to writing files outside the target directory.
This is a second-stage flaw. Exploitation takes local access and valid user credentials on the PCM600 machine [3]. An outside attacker has to get onto that machine first [3]. From there, an ordinary login is enough to elevate privileges and take control of the host [3].
The workaround is set in Services.msc, on the Log On tab of the ABBPCMSchedulerService instance that matches the installed PCM600 version [6]. The account chosen there needs the Log on as a service right [7]. On IEDs with authentication enabled, the Scheduler tool then has to be used from that same Windows account [8]. With the change in place, the service runs with the PCM600 operator's rights and no longer as LocalSystem [1].
The archive flaw is classed as CWE-22 path traversal [12], and CISA's summary lists file overwrites among the outcomes [17]. The mitigations listed under it repeat the Scheduler Service steps word for word [13]. Both lists also carry the same certificate advice: enable PCM600's setting to always trust IED security certificates only when PCM600-to-IED communication happens in a secure and trusted environment [14].
The two flaws are tracked as CVE-2026-15952 and CVE-2026-15953, both against version 2.14 and earlier [1]. Abhinav Agarwal reported them to CISA [10], which points readers to ABB advisories 2NGA003170 and 2NGA003179 [15]. CISA also recommends keeping control system devices off the internet and putting control networks behind firewalls, isolated from business networks [16]. The advisory lists a workaround, no fixed release and no reported exploitation [18].
What to watch
- Whether ABB advisories 2NGA003170 and 2NGA003179 name a fixed PCM600 release above 2.14.
- Any report of exploitation or a public proof-of-concept for CVE-2026-15952 or CVE-2026-15953.
- Whether ABB or CISA say what privileges the archive extraction writes with, which sets how far the file-overwrite flaw reaches.