CVE Explorer
CVE-2026-32666
WebCTRL systems that communicate over BACnet inherit the protocol's lack
of network layer authentication. WebCTRL does not implement additional
validation of BACnet traffic so an attacker with network access could
spoof BACnet packets directed at either the WebCTRL server or associated
AutomatedLogic controllers. Spoofed packets may be processed as
legitimate.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-290","description":"CWE-290 Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-290","description":"CWE-290","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"WebCTRL Premium Server","vendor":"Automated Logic","versions":[{"lessThan":"v8.5","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-290","description":"CWE-290 Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-290","description":"CWE-290","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-078-08.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/references/2
{"url":"https://www.automatedlogic.com/en/company/security-commitment/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/references/0
{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-08"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:87a5a4607dca276b4e8b1c246b83507ffe68309dd015abb1d22e0bf8ac30dbef · sha256:3f1b6ce4e91d6692… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.