CVE-2026-30512
Scheidt & Bachmann · entervo HMI
A local privilege escalation flaw in Scheidt & Bachmann entervo HMI allows low-privileged users to escape kiosk mode and execute arbitrary commands with administrator privileges via the PDF viewer.
Executive summary
A high-severity local privilege escalation vulnerability in Scheidt & Bachmann entervo HMI allows authenticated users to bypass kiosk restrictions and gain full administrative control over the underlying system.
Vulnerability
The vulnerability exists within the application's external PDF viewer functionality. An authenticated low-privileged user can leverage the print feature to escape the restricted kiosk environment and execute arbitrary commands with local administrator privileges.
Business impact
The ability for a low-privileged user to gain full administrative access to an HMI system presents a significant security risk. Successful exploitation could lead to total system compromise, unauthorized data access, and potential disruption of critical infrastructure operations. Given the CVSS score of 7.8, this vulnerability is categorized as high severity and requires immediate attention to prevent unauthorized escalation.
Remediation
Immediate Action: Administrators must update the Scheidt & Bachmann entervo HMI software to version V2 R5 P0 M5 or later to resolve the kiosk escape flaw.
Proactive Monitoring: Security teams should monitor system logs for unusual process execution patterns or attempts to invoke system-level commands from within the HMI application environment.
Compensating Controls: Restrict access to the application manual and disable print functionality if the update cannot be applied immediately, as these are the primary vectors for the kiosk escape.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as attributed to the technical write-up referenced in the CVE record.
Analyst recommendation
This vulnerability represents a significant risk to the integrity and security of the entervo HMI environment. Because the exploit vector involves common application features like the PDF viewer and printing, it is highly accessible to any user with local access to the kiosk. Organizations should prioritize patching to version V2 R5 P0 M5 immediately to eliminate the possibility of privilege escalation and protect against unauthorized administrative access.