← Vulnerability feed

Vulnerability record · CVE-2026-22619 · published 16 April 2026

CVE-2026-22619: Eaton intelligent power protector uncontrolled search path element vulnerability

Eaton · Intelligent Power Protector

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.

9.9 CVSS 3.1 Critical EPSS 0.32% · top 77.1% CWE-427 · Uncontrolled search path element
9.9CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download center.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22619 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-23277Eaton intelligent power manager code injection vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize c…EPSS 0.96%10.0CVE-2021-23279Eaton intelligent power manager improper input validation vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability induced due to improper inpu…EPSS 27%9.9CVE-2021-23280Eaton intelligent power manager unrestricted file upload vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an a…EPSS 0.87%9.6CVE-2021-23278Eaton intelligent power manager improper input validation vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability induced due to improper input …EPSS 1.0%8.8CVE-2021-23276Eaton intelligent power manager sql injection vulnerabilityEaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packe…EPSS 0.79%7.5CVE-2026-22616Eaton intelligent power protector improper restriction of authentication attempts vulnerabilityEaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rat…EPSS 0.32%7.4CVE-2026-22617Eaton intelligent power protector vulnerabilityEaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and…EPSS 0.17%7.2CVE-2026-22615Eaton intelligent power protector improper input validation vulnerabilityDue to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and …EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-22619), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.