CVE-2026-9593: CWE-427 Uncontrolled Search Path Element in Endress+Hauser FDI Package library
CVE-2026-9593 is a high-severity vulnerability in the Endress+Hauser FDI Package library version 1.00.00. It involves an uncontrolled search path element that allows an attacker with elevated privileges and access to the host system to enable a debug interface by placing a crafted file in the application directory. This can lead to unauthorized access to connected devices and potential exposure, modification, or disruption of device data or operation.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-9593 affects the iDTM FDI component of the Endress+Hauser FDI Package library version 1.00.00. It is classified under CWE-427 (Uncontrolled Search Path Element). An attacker who already has elevated privileges and access to the host system can exploit this by placing a specially crafted file in the application directory, which enables the debug interface. This unauthorized activation of the debug interface may allow the attacker to access connected devices improperly and potentially expose, modify, or disrupt device data or operations. The CVSS 4.0 base score is 8.4, indicating high severity, with attack vector local, low attack complexity, no user interaction required, and high impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation requires elevated privileges and local access to the host system. The attacker can enable a debug interface that is not intended to be active, leading to unauthorized access to connected devices. This can result in exposure of sensitive device data, unauthorized modification, or disruption of device operations. The vulnerability does not affect cloud services and no known exploits are reported in the wild.
Mitigation Recommendations
No official patch or remediation level has been published by the vendor as of the current information. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict elevated access to trusted users only and monitor for unauthorized file placements in the application directory to reduce risk.
CVE-2026-9593: CWE-427 Uncontrolled Search Path Element in Endress+Hauser FDI Package library
Description
CVE-2026-9593 is a high-severity vulnerability in the Endress+Hauser FDI Package library version 1.00.00. It involves an uncontrolled search path element that allows an attacker with elevated privileges and access to the host system to enable a debug interface by placing a crafted file in the application directory. This can lead to unauthorized access to connected devices and potential exposure, modification, or disruption of device data or operation.
CVSS v4.0
Score 8.4high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-9593 affects the iDTM FDI component of the Endress+Hauser FDI Package library version 1.00.00. It is classified under CWE-427 (Uncontrolled Search Path Element). An attacker who already has elevated privileges and access to the host system can exploit this by placing a specially crafted file in the application directory, which enables the debug interface. This unauthorized activation of the debug interface may allow the attacker to access connected devices improperly and potentially expose, modify, or disrupt device data or operations. The CVSS 4.0 base score is 8.4, indicating high severity, with attack vector local, low attack complexity, no user interaction required, and high impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation requires elevated privileges and local access to the host system. The attacker can enable a debug interface that is not intended to be active, leading to unauthorized access to connected devices. This can result in exposure of sensitive device data, unauthorized modification, or disruption of device operations. The vulnerability does not affect cloud services and no known exploits are reported in the wild.
Mitigation Recommendations
No official patch or remediation level has been published by the vendor as of the current information. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict elevated access to trusted users only and monitor for unauthorized file placements in the application directory to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERTVDE
- Date Reserved
- 2026-05-26T14:03:32.923Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a703651bf32cb7a3418322b
Added to database: 08/03/2026, 06:33:53 UTC
Last enriched: 08/03/2026, 06:47:55 UTC
Last updated: 08/03/2026, 07:00:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.