Schneider Electric SCADAPack Credential Flaw Exposes RTU Authentication Data

Schneider Electric CVE-2026-81861 flaw lets Secure Lock expose SCADAPack RTU credentials. See affected models, risks and RBAC mitigation.

Text generated by artificial intelligence, published without human review. AI transparency

Schneider Electric SCADAPack Credential Flaw Exposes RTU Authentication Data
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Schneider Electric has disclosed a credential-protection vulnerability affecting multiple SCADAPack remote terminal unit families used in energy and critical manufacturing environments worldwide.

Tracked as CVE-2026-81861, the flaw concerns the legacy Secure Lock function. Authentication information may be exposed, potentially allowing an unauthorized party to access RTU functionality or configuration.

Schneider Electric issued its initial advisory on September 8, 2026. CISA republished the disclosure on September 15, 2026, attributing the report to security researcher Abhinav Agarwal.

The vulnerability carries a CVSS v3.1 base score of 6.5, placing it in the medium-severity range. No active exploitation has been reported, and the issue is not identified as an entry in CISA’s Known Exploited Vulnerabilities catalog.

Every Listed SCADAPack Version Is Considered Affected

The CISA industrial control systems advisory assigns known_affected status to seven Schneider Electric product families:

  • SCADAPack 47x — vers:all/*
  • SCADAPack 47xi — vers:all/*
  • SCADAPack 47xd — vers:all/*
  • SCADAPack 470R — vers:all/*
  • SCADAPack 57x — vers:all/*
  • SCADAPack 3xx — vers:all/*
  • SCADAPack 32 — vers:all/*

The vers:all/* designation means the disclosure does not restrict exposure to particular firmware or software releases. Operators should consequently treat all versions of the listed families as potentially vulnerable unless Schneider Electric provides narrower guidance.

The advisory summary focuses on the 47x, 47xi, 47xd, 470R, and 57x product lines as SCADAPack x70 RTUs. However, the detailed affected-product table also names SCADAPack 3xx and SCADAPack 32. Those additional families should not be omitted during asset discovery or risk assessment.

SCADAPack RTUs provide communications for remote monitoring and control. Their deployment in critical manufacturing and energy environments makes accurate inventory especially important, even though the documented effect of this flaw is limited to confidentiality.

Secure Lock Does Not Adequately Protect Credentials

CVE-2026-81861 is classified as CWE-522, or insufficiently protected credentials. The weakness resides in Secure Lock, a legacy access-control feature retained for compatibility with older systems.

Successful exploitation may reveal authentication information and provide unauthorized access to RTU functions. CISA describes the resulting risk more specifically as unauthorized access to RTU configuration through Secure Lock.

The published CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

That vector describes a vulnerability reachable over a network, with low attack complexity and no requirement for existing privileges. Exploitation does require user interaction, although the disclosure does not explain what action a user would need to perform.

The confidentiality rating is high. By contrast, the assessment assigns no direct integrity or availability impact and does not indicate that exploitation crosses a security-authority boundary.

This distinction matters for operational risk analysis. The published assessment does not describe an attacker changing process values, disrupting RTU operation, or causing a loss of service through the vulnerability alone. It does, however, identify the possible disclosure of authentication material and access to sensitive configuration information.

Those credentials could be security-relevant beyond the immediate confidentiality loss, but the disclosure does not document additional attack stages. Organizations should avoid assuming either that broader compromise is inevitable or that exposed authentication data is harmless.

No Patch or Fixed Version Has Been Announced

The disclosure does not identify a security patch, corrected firmware release, or unaffected version. Instead, Schneider Electric recommends moving away from Secure Lock wherever operational and compatibility requirements permit.

Role-Based Access Control is the preferred mechanism for SCADAPack 47x devices. Secure Lock should remain enabled only where legacy-system dependencies make it necessary.

Operators should enable and configure RBAC according to the product documentation, particularly the sections covering administrator security guidance and role-based access controls. Schneider Electric also directs customers to the SCADAPack Cybersecurity Guide for device-hardening and secured-communications guidance.

Relevant documentation is available through the company’s RemoteConnect and SCADAPack x70 Utilities documentation portal. Customers needing product-specific help can contact a local Schneider Electric representative or the company’s Industrial Cybersecurity Services team.

Because no fixed release is specified, the practical response is configuration-based mitigation combined with reduced network exposure. Asset owners should document every device still using Secure Lock and establish whether each legacy dependency can be removed.

Segmentation and the RTU Firewall Can Reduce Exposure

Schneider Electric recommends separating trusted and untrusted networks and tightly controlling traffic between them. The RTU Firewall Service should also be enabled to block unauthorized access to device services and shrink the reachable attack surface.

Control and safety networks should remain isolated from business systems. RTUs and other control devices should not be directly accessible from the Internet, while inbound and outbound communications should be limited to required hosts, protocols, and services.

Where remote access is operationally necessary, organizations should use secured connections such as VPNs. VPN software must be kept current, but a VPN alone does not make the connecting endpoint trustworthy. Devices entering the control environment through remote-access infrastructure require their own security assessment.

Physical protections remain relevant as well. Controllers should be housed in locked cabinets, and operators should avoid leaving them in Program mode. Engineering or programming workstations should connect only to networks containing the devices they are intended to manage.

Removable media should be scanned before it reaches isolated networks or attached terminals. Mobile equipment that has connected to another network should not subsequently enter a safety or control environment without appropriate sanitization.

Any new firewall rule, access-control policy, or isolation measure should undergo an impact analysis before deployment. Poorly tested defensive changes can interrupt required industrial communications even when the underlying security objective is valid.

Exploitation Has Not Been Reported or Added to KEV

There is no reported evidence that CVE-2026-81861 is being exploited in the wild. The vulnerability is also not identified in the available disclosure as part of CISA’s Known Exploited Vulnerabilities catalog, and no KEV remediation deadline has been assigned.

That means the advisory documents an exposed weakness rather than a confirmed active exploitation campaign. The network-accessible attack path, lack of required privileges, and potential disclosure of authentication information nevertheless justify prompt review.

Operators should look for unexpected access to RTU configuration interfaces, unexplained authentication activity, unauthorized changes to access-control settings, and connections from systems that do not normally administer SCADAPack devices. No vulnerability-specific indicators of compromise have been published.

Organizations finding suspicious activity should preserve relevant network, authentication, and device-management records. They should then follow internal incident-response procedures and report pertinent findings to CISA for correlation and tracking.

The immediate priority is clear: identify every affected SCADAPack unit, determine where Secure Lock remains in use, migrate to RBAC where possible, and restrict access to devices that cannot yet leave the legacy mechanism behind.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsSCADAPack vulnerabilityCVE-2026-81861Schneider ElectricRTU securitySecure LockRBAC mitigation
Back to home