CVE-2018-19027: Omron Cx-One

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.

Affected products

  • Omron Cx-One: up to and including 4.50
  • Omron Cx-Protocol: up to and including 2.0

Published 2019-01-30. Last modified 2026-06-17.