CVE-2026-27546
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
- Published Sep 16, 2026
- CVSS 9.8 critical
- 1.0% chance of exploitation in the next 30 days (EPSS)
Affected software
- Carlo Gavazzi Automation YL212CEI8M1IO
- Pepperl+Fuchs ICE2-8IOL-G65L-V1D
- Pepperl+Fuchs ICE2-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE2-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE2-8IOL1-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D
- Pepperl+Fuchs ICE3-8IOL-G65L-V1D-Y
- Pepperl+Fuchs ICE3-8IOL-K45P-RJ45
- Pepperl+Fuchs ICE3-8IOL-K45S-RJ45
- Pepperl+Fuchs ICE3-8IOL1-G65L-V1D
- Phoenix Contact IOL MA8 EIP DI8
- Phoenix Contact IOL MA8 PN DI8