CVE-2026-79679
8.7B&R Industrial Automation GmbH · mapp Services
A use of weak credentials vulnerability in B&R Industrial Automation GmbH mapp Audit within mapp Services allows potential system compromise.
Executive summary
B&R Industrial Automation GmbH mapp Services is vulnerable to a credential weakness that could allow an attacker to achieve high-impact system manipulation.
Vulnerability
This vulnerability involves the use of weak credentials (CWE-1391) within the mapp Audit component. The flaw is reachable by an unauthenticated attacker over the network, though it requires specific conditions to be met (AT:P).
Business impact
The presence of weak credentials in an industrial automation environment poses a significant risk to operational integrity. With a CVSS score of 8.7, this vulnerability presents a high risk for unauthorized system configuration changes or process disruption, which could lead to severe downtime or safety concerns in industrial settings.
Remediation
Immediate Action: Upgrade mapp Services to version 6.8.0 or later as mandated by the vendor security advisory.
Proactive Monitoring: Review system access logs for anomalous authentication attempts or unauthorized configuration changes within the mapp Audit environment.
Compensating Controls: Implement strict network segmentation to ensure the affected industrial services are not exposed to the public internet, and utilize internal firewalls to limit access to authorized personnel only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high severity of this vulnerability, organizations must treat the update to version 6.8.0 as a priority. Administrators should coordinate with industrial control system teams to schedule the necessary updates during the next available maintenance window to minimize operational impact while addressing the risk of unauthorized access.