CVE-2026-27546: Carlo Gavazzi Automation YL212CEI8M1IO

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

Affected products

Published 2026-09-16. Last modified 2026-09-16.