CVE-2026-5434

MEDIUM

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potential...

Affects 0 products across 2 vendors.

BCS4.22
CVSS 3.15.9
EPSS0.0%
Percentile13th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-538: CWE-538
Related Attack Patterns (CAPEC)
CAPEC-95 WSDL Scanning
via CWE-538

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Honeywell Control Network Module (CNM) is vulnerable to the insertion of sensitive information into an unintended directory, which could lead to unauthorized access to protected data.

BSID: BS-2026-GLOBAL-268883-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-5434?
Honeywell Control Network Module (CNM) is vulnerable to the insertion of sensitive information into an unintended directory, which could lead to unauthorized access to protected data.
What is the CVSS score for CVE-2026-5434?
CVE-2026-5434 has CVSS 5.9 (Medium). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. EPSS: 0.0%.
Is CVE-2026-5434 actively exploited?
No confirmed active exploitation of CVE-2026-5434 as of 2026-07-28.
How do I remediate CVE-2026-5434?
Priority: MEDIUM. PSIRT: [email protected]
What systems are affected by CVE-2026-5434?
CVE-2026-5434 affects: Files, Honeywell.
Vulnerability Details
CVE IDCVE-2026-5434
BSIDBS-2026-GLOBAL-268883-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Published2026-05-21
Last Modified2026-07-27
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker could exploit this vulnerability by probing system files, potentially gaining unintended access to sensitive data stored in the CNM.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Files —
Honeywell —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 67 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash6f2d54b51ea5077af8cebb96306aecc152e54af0fcbc043edc851f6c92e766812001c74ef96a6ece60bb2c9878e3fbb958513889c3c296bb5581b7f154e5d539
Related CVEs affecting Files
CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h... CVE-2025-32510 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ova... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-2025-48148 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper ...
View all Files CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →