CVE-2026-32666

HIGH

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with ne...

Affects 0 products across 3 vendors.

BCS4.94
CVSS 3.17.5
EPSS0.3%
Percentile25th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-290: CWE-290
Related Attack Patterns (CAPEC)
CAPEC-59 Session Credential Falsification through Prediction
via CWE-290
CAPEC-60 Reusing Session IDs (aka Session Replay)
via CWE-290
CAPEC-459 Creating a Rogue Certification Authority Certificate
via CWE-290
CAPEC-476 Signature Spoofing by Misrepresentation
via CWE-290
CAPEC-667 Bluetooth Impersonation AttackS (BIAS)
via CWE-290
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

WebCTRL systems communicating over BACnet are vulnerable to spoofed BACnet packets due to the protocol's lack of network layer authentication and WebCTRL's lack of additional validation.

BSID: BS-2026-GLOBAL-273838-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-32666?
WebCTRL systems communicating over BACnet are vulnerable to spoofed BACnet packets due to the protocol's lack of network layer authentication and WebCTRL's lack of additional validation.
What is the CVSS score for CVE-2026-32666?
CVE-2026-32666 has CVSS 7.5 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. EPSS: 0.3%.
Is CVE-2026-32666 actively exploited?
No confirmed active exploitation of CVE-2026-32666 as of 2026-05-30.
How do I remediate CVE-2026-32666?
Priority: HIGH. Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-08
What systems are affected by CVE-2026-32666?
CVE-2026-32666 affects: Associated, Automatedlogic, Protocol.
Vulnerability Details
CVE IDCVE-2026-32666
BSIDBS-2026-GLOBAL-273838-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Published2026-03-21
Last Modified2026-03-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker with network access can spoof BACnet packets directed at the WebCTRL server or associated AutomatedLogic controllers. These spoofed packets may be processed as legitimate by the system.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Associated —
Automatedlogic —
Protocol —
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 126 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashbcd1adde3799b860fb337afb67818206d9664ec8426558f54984b4528f034d5af46f74e337bfa8e26a97b741ba600c8e6ba3509939a07c23acbf41173f25b264
Related CVEs affecting Associated
CVE-2024-2086 10.0 The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Ga... CVE-2025-40914 9.8 Perl CryptX before version 0.087 contains a dependency that may be susceptibl... CVE-2026-5229 9.8 The Form Notify plugin for WordPress is vulnerable to Authentication Bypass i... CVE-2024-45337 9.1 Applications and libraries which misuse connection.serverAuthenticate (via ca... CVE-2025-10293 8.8 The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulner...
View all Associated CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →