PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0936 ABB CVE debrief

CVE-2026-0936 is a medium-severity information disclosure issue affecting ABB B&R PVI client versions prior to 6.5.0. According to the advisory, an authenticated local attacker could abuse client-side logging to gather credential information processed by the PVI client. Logging is disabled by default and must be explicitly enabled, which reduces exposure but does not eliminate risk where troubleshooting or debugging logging is turned on.

Vendor
ABB
Product
PVI
CVSS
MEDIUM 5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-29
Original CVE updated
2026-05-05
Advisory published
2026-01-29
Advisory updated
2026-05-05

Who should care

Organizations running ABB B&R PVI client software prior to 6.5.0, especially OT/industrial environments where local users, support staff, or shared administrative access can enable client logging. Security and operations teams should care most if client-side troubleshooting logs are used on production systems.

Technical summary

The issue is an Insertion of Sensitive Information into Log File weakness affecting the PVI client side. The advisory states that an authenticated local attacker may obtain credential information that is processed by the PVI client application when logging is enabled. The logging function is disabled by default. The source also notes that the problem does not affect security-related logging of the PVI server component and is corrected in PVI 6.5.0.

Defensive priority

Medium. The vulnerability is local and requires authentication, but it can expose credentials if client logging is enabled in environments where logs are retained or accessible to unintended users. Prioritize remediation for systems that enable PVI client logging for support or analysis.

Recommended defensive actions

  • Upgrade ABB B&R PVI to version 6.5.0 or later.
  • If immediate upgrading is not possible, keep PVI client logging disabled except when strictly necessary for troubleshooting.
  • When logging must be enabled, restrict filesystem access so only the intended user can read the log directory.
  • Delete client-side log files securely once they are no longer needed.
  • Review any workflows that collect or archive PVI client logs to ensure sensitive information is not retained longer than necessary.

Evidence notes

The source advisory (ICSA-26-125-02, republished from ABB PSIRT SA26P001) states: the affected product is B&R PVI client versions prior to 6.5; the issue may be abused by an authenticated local attacker to gather credential information processed by the client; and logging is disabled by default. The remediation section says the issue is corrected in PVI 6.5.0 and that the issue is limited to PVI client-side logging, not security-related server logging. CISA’s source item was initially published on 2026-01-29 and republished on 2026-05-05.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-0936 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-0936

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-0936 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0936

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-125-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://psirt.abb.com/csaf/2026/sa26p001.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/SA26P001-2862434c.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-125-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.