CVE-2026-8072Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based on a secure cryptographic scheme, but rather on a weak hashing algorithm, which could allow an attacker to carry out a privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-12: 3Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 305-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Generación insegura de credenciales de acceso SAT en #Ingecon EMS Board #CVE CVE-2026-8072 https://www.incibe.es/incibe-cert/alerta-temprana/avisos-sci/generacion-insegura-de-credenciales-de-acceso-sat-en-ingecon-ems-board #AvisosDeSeguridad #CNA #SCI

    Post summary

    Incibe has announced CVE-2026-8072, noting insecure credential generation on the Ingecon EMS board, with no evidence of active exploitation, PoC, or patch information.

    01030352
    42.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Ingecon Sun EMS Board Insecure SAT Credential Generation (CVE-2026-8072) The Ingecon Sun EMS Board uses a weak hashing algorithm instead of a secure cryptographic scheme to generate secret access credentials for its local SAT (Technical Support) functionality. This allows attackers to predict or brute-force credentials, enabling privilege escalation. The vulnerability affects multiple firmware versions and can lead to unauthorized high-privilege access on the device. 👉Affected: Ingecon Sun EMS Board (AAX1055CT or earlier, ABU1001_P or earlier, ACL1201_B or earlier, ACL1200AL or earlier, ABH1027_K or earlier, ABH1007_Z or earlier, ABS1009_L or earlier, ABS1005_T or earlier, ACB1005_A or earlier, AAX1031CN or earlier) | Upgrade to April 28, 2026 versions.

    Post summary

    CVE-2026-8072 exposes weak hashing in Ingecon Sun EMS Board, permitting credential brute‑force and privilege escalation; users are urged to upgrade to the April 28, 2026 firmware to remediate.

    00020104
    187 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8072 Insecure Credential Generation in Ingecon Sun EMS Board Technical Support Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8072

    Post summary

    CVE‑2026‑8072 highlights insecure credential generation in Ingecon Sun EMS board’s technical support access. No PoC, exploit, patch, or active exploitation claims are provided.

    0000044
    4.0K followersView on X

Explore more