CVE-2026-27553: Carlo Gavazzi Automation YL212CEI8M1IO

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

Affected products

Published 2026-09-16. Last modified 2026-09-19.