CVE-2026-4769 CRITICAL

CVE-2026-4769: Unauthenticated Access to Internal Diagnostic Interface

Vendor Wago
Product 0765-110x/0100-0000
Weakness CWE-912
Published July 13, 2026
Last update July 13, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system compromise.

Key dates

02Disclosure timeline

July 13, 2026 CVE published
July 13, 2026 Record updated