Skip to content

Security1 publisher2 min readPublished

GX Works3 accepts an invalid block password in every version Mitsubishi Electric shipped

CVE-2026-15688 lets someone running the software locally get past a block password and edit the loaded module in memory. Mitsubishi Electric's remedy is a new build plus a security setting applied project by project.

The Watch · Security desk

Illustration accompanying GX Works3 accepts an invalid block password in every version Mitsubishi Electric shipped

What happened

  • CISA's advisory on CVE-2026-15688 says a local attacker can authenticate to Mitsubishi Electric GX Works3 with an invalid block password by running the product and modifying part of its executable module in memory.
  • Past that check, the attacker can view, tamper with, destroy or delete the control programs the block password was set to protect.
  • Every version of GX Works3 and of the bundled Motion Control Settings is listed as affected under the single CVE.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anyone who can execute the engineering software on that workstation, a contractor with a project copy included, can read and rewrite protected blocks without the password.
  • cost Getting protected costs more than an installer run, because every existing project has to be opened and saved again at security version 2 before the setting does anything.
  • constraint The network half of Mitsubishi Electric's mitigation list does not reach a local attacker, so program integrity now rests on who can run code on the engineering PC.

A block password is enforced by the software that opens the project, and CVE-2026-15688 is a defect in that enforcement. CISA classes it as CWE-303, an authentication algorithm implemented incorrectly, so the check accepts a password that is wrong [1]. The attacker never needs the real one. The route CISA describes is to run the affected product and modify part of its executable module in memory [1]. The check runs inside a process the attacker already controls.

Local, in this advisory, means being able to execute the product on the machine [1]. That covers a maintenance contractor with a copy of the project and it covers any payload running with the engineer's rights on the workstation.

Mitsubishi Electric's instructions have two steps, and CISA files them as workarounds. Download GX Works3 1.096A or later, install it, then set the security version for projects to "2", following the operating manual section on preventing illegal access to and falsification of data [5]. For Motion Control Settings the build is 1.070Y or later and the reference is section 12.5 of the help file [6]. Because the CVE lists all versions of both products as affected, the download is not a fixed build in the usual sense, and the protection comes from the project setting [3][14].

Five further mitigations sit under the advisory [15]. Two concern network reachability: keep the workstation on a LAN with remote logins from untrusted networks, hosts and users blocked [7], and use a firewall or VPN, with remote login limited to trusted users, when the machine is connected to the internet [8]. Two concern how hostile code arrives: stop users clicking links or opening attachments from untrusted sources [9], and install antivirus on the host [10]. The fifth is physical access, to the computer and to the computers and network devices that can talk to it [11]. For a bug that requires local execution, those last three decide who gets to trigger it.

Mayeul Fargier, Erwan Cordier and Noé Flatreaud reported the vulnerability to Mitsubishi Electric [12]. CISA's advisory does not include a CVSS score [13]. The deployment area is worldwide and the sector listed is critical manufacturing [4].

What to watch

  • Whether Mitsubishi Electric ships a build that corrects the authentication check itself rather than relying on the project security version setting.
  • Any public proof of concept for the in-memory modification, or a CVSS score added to the CISA advisory.
  • Whether projects saved at security version 2 stay usable on shop floors still running older GX Works3 installs.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories