CVE-2026-2328

7.5

WAGO · Device Sphere, Solution Builder

An unauthenticated remote attacker can exploit insufficient input validation in WAGO products to perform path traversal and access sensitive backend information.

Executive summary

WAGO Device Sphere and Solution Builder are vulnerable to an unauthenticated path traversal attack that allows remote attackers to access sensitive information.

Vulnerability

This vulnerability involves improper filtering of special elements, specifically path traversal, occurring when an unauthenticated remote attacker provides malicious input to the application. The flaw allows the attacker to bypass intended access controls and read sensitive data from backend components.

Business impact

The exploitation of this vulnerability can lead to the unauthorized disclosure of sensitive configuration data or system information, potentially facilitating further attacks against the infrastructure. With a CVSS score of 7.5, this issue represents a High severity risk that could lead to significant data exposure if left unaddressed. Organizations relying on these products for critical industrial or automation tasks face potential operational and compliance risks due to the loss of confidentiality.

Remediation

Immediate Action: Update WAGO Device Sphere to version 1.2.2 or later and WAGO Solution Builder to version 2.4.2 or later to apply the necessary input validation fixes.

Proactive Monitoring: Review web server and application access logs for anomalous directory traversal patterns, such as sequences involving multiple dot-slash characters, targeting sensitive backend files.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured to inspect and block incoming HTTP requests containing directory traversal payloads.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the High severity of this vulnerability and the potential for unauthorized data access, administrators should prioritize the application of the vendor-provided security updates. Immediate patching is the most effective way to eliminate this risk, as path traversal flaws are often leveraged by attackers to gather intelligence for more complex intrusions. Ensure that all affected instances are identified and updated across the enterprise environment to maintain a secure posture.

More WAGO CVEs

Sources

Originally found and disclosed by Marvin Ramsperger from SySS GmbH, per the CVE Program record.