- CISA's advisory ICSA-26-274-03 lists two flaws, CVE-2026-15952 and CVE-2026-15953, in ABB PCM600 version 2.14 and earlier. No public exploitation has been reported to CISA.
- A service running as LocalSystem is reachable by standard users, and archive paths are poorly checked. The privilege flaw needs local access and valid credentials and gives control of the host.
- ABB's workaround reduces the risk of privilege escalation but does not fix the flaw. Teams should find PCM600 installs and check which account runs the Scheduler Service.
Engineering software is trusted by design. Tools like ABB's Protection and Control IED Manager PCM600 are built to manage other equipment. Because these tools manage other equipment, the hosts that run them are likely to hold a privileged place on the network. That is why control of such a host deserves serious attention.
A new CISA advisory describes flaws in PCM600 that could give an attacker control of the host running it. The advisory does not say any managed device was affected. The flaws are also not exotic. A background service was given more power than the people who use it.
What CISA reported
CISA published advisory ICSA-26-274-03 on October 1, 2026. It covers PCM600 versions up to and including 2.14 and lists two CVEs: CVE-2026-15952 and CVE-2026-15953. Abhinav Agarwal reported the vulnerabilities to CISA.
The advisory says successful exploitation could let an attacker escalate privileges or overwrite files. CISA says no known public exploitation targeting these flaws has been reported to it.
How the first flaw works
PCM600 installs a Scheduler Service. It runs under the Windows LocalSystem account, which has the highest level of local access on a machine.
The problem is who can reach it. CISA says permissions on the service are granted to standard PCM600 users through the local users group. So an ordinary user can steer something that runs with system-level power.
The advisory says an attacker needs local access and valid user credentials. That limits who can try it. It does not remove the risk on a machine where several people hold standard logins. CISA says the result is control of the affected host. It classes the weakness as CWE-732, incorrect permission assignment for a critical resource.
How the second flaw works
The second issue is in how PCM600 handles project archive files. CISA says the software does not check the file paths inside an archive well enough.
A crafted archive could therefore write files outside the folder it was meant to unpack into. This weakness is called path traversal, listed as CWE-22.
The advisory does not say how the two flaws might be combined. That would be speculation.
What ABB recommends
ABB offers a workaround, not a fix. The advisory says it does not correct the underlying vulnerability, but it reduces the risk of privilege escalation.
The workaround is to run the ABBPCMSchedulerService under the same Windows account used to operate PCM600. That account needs the "Log on as a service" privilege. Where IED authentication is on, the Scheduler tool must use that same account.
For sites using IED security certificates, the setting that trusts those certificates automatically should be enabled only when PCM600 talks to the IED in a secure, trusted environment. It points to ABB advisories 2NGA003170 and 2NGA003179 for detail.
The advisory lists the same steps under the archive flaw. It does not say they address that flaw, so teams should not assume they do.
The idea behind the flaw
Permissions are often set for convenience. A service gets high rights so it works, and users get access so they can use it. Each choice looks reasonable alone. Together they build a short path from a normal login to full control of the host.
The lesson here is that engineering tools sit on a trust boundary. Because they are trusted to work with other equipment, the account that runs them deserves close scrutiny. The advisory describes impact on the host only.
Questions to put to your team
Do we know every installation of PCM600, and is any at version 2.14 or earlier? Which Windows account runs the Scheduler Service on each one? Who else has a standard login on those machines?
Where do project archives come from, and who can hand one to an engineer? Are control system networks kept off the internet and separate from business networks, as CISA advises?
A tool that manages other devices deserves a close look at the account behind its service. Check it now, while no exploitation has been reported.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





