CVE-2026-5434
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potential...
Affects 0 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Honeywell Control Network Module (CNM) is vulnerable to the insertion of sensitive information into an unintended directory, which could lead to unauthorized access to protected data.
BSID: BS-2026-GLOBAL-268883-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-5434?
What is the CVSS score for CVE-2026-5434?
Is CVE-2026-5434 actively exploited?
How do I remediate CVE-2026-5434?
What systems are affected by CVE-2026-5434?
| CVE ID | CVE-2026-5434 |
|---|---|
| BSID | BS-2026-GLOBAL-268883-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Published | 2026-05-21 |
| Last Modified | 2026-07-27 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Source: NIST NVD / MITRE CVE Database
An attacker could exploit this vulnerability by probing system files, potentially gaining unintended access to sensitive data stored in the CNM.
Exploitation Likelihood: MEDIUM
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 6f2d54b51ea5077af8cebb96306aecc152e54af0fcbc043edc851f6c92e766812001c74ef96a6ece60bb2c9878e3fbb958513889c3c296bb5581b7f154e5d539 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →