The Cybersecurity and Infrastructure Security Agency (CISA) has issued industrial security advisory ICSA-26-274-03 warning electric utility operators of critical privilege escalation and path traversal vulnerabilities in ABB Protection and Control IED Manager PCM600. Tracked as CVE-2026-15952 and CVE-2026-15953, the flaws allow local authenticated attackers to achieve NT AUTHORITYSYSTEM privileges on substation engineering workstations and overwrite arbitrary system binaries during project archive decompression, threatening the integrity of IEC 61850 protective relay configurations across power transmission grids.
The Role of PCM600 in Electric Power Grid Protection
The ABB PCM600 software is a mission-critical engineering suite used by power utility technicians to configure, parameterize, test, and commission Intelligent Electronic Devices (IEDs) across high-voltage electrical substations. The tool directly interacts with protective relays (such as transformer differential protection and transmission line distance protection) communicating over IEC 61850 GOOSE and MMS protocols.
If an attacker compromises an engineering workstation running PCM600, they gain the ability to alter relay trip thresholds, suppress fault detection interlocks, or inject malicious logic into protective relays, potentially causing physical transformer destruction or cascading blackout events.
Technical Dissection: Insecure Service Permissions & Zip Slip
The advisory identifies two distinct architectural vulnerabilities:
1. Scheduler Service ACL Misconfiguration (CVE-2026-15952, CWE-269)
PCM600 installs a background Windows service (ABB.PCM600.SchedulerService.exe) designed to automate scheduled relay diagnostics and configuration backups. This service executes under the supreme LocalSystem account.
However, the file permissions and task definitions associated with the scheduler folder (C:ProgramDataABBPCM600Scheduler) granted FILE_ALL_ACCESS or write permissions to the built-in BUILTINUsers group. A standard local user (such as a compromised field technician account) can modify scheduled job configuration scripts or replace target task executables with a malicious binary. When the scheduler triggers, the payload executes as SYSTEM.
2. Project Archive Path Traversal (CVE-2026-15953, CWE-22)
PCM600 projects are frequently shared among utility engineers as compressed project archives (with .pcmp extensions). When extracting these archives, the internal decompression library failed to sanitize directory traversal sequences (../) embedded in archive header filenames:
# Archive containing malicious directory traversal entry:
# Filename in .pcmp zip header:
../../../../Windows/System32/evil_payload.dll
When an unsuspecting protection engineer opens the project archive in PCM600, the application extracts the nested DLL directly into Windows system directories or an unquoted service path. Upon subsequent reboot or service invocation, the hijacked DLL is executed with administrative privileges.
| Vulnerability Identifier | Weakness Type | Base CVSS Score | Prerequisites | Grid Threat Level |
|---|---|---|---|---|
| CVE-2026-15952 | Improper Privilege Management (CWE-269) | 7.8 High | Local user account on engineering PC | SYSTEM privilege escalation on substation laptop |
| CVE-2026-15953 | Path Traversal / Zip Slip (CWE-22) | 7.8 High | Opening a manipulated .pcmp project file | Arbitrary file overwrite & DLL hijacking |
Protective Engineering Action Plan
- Apply ABB Patch Release: Electric utilities must install ABB PCM600 update rollup v3.0 Hotfix 1 or version 2.12 with official hotfixes, which restricts scheduler file ACLs and enforces strict canonical path checking during project decompression.
- Harden Substation Workstation ACLs: Audit directory permissions on
C:Program Files (x86)ABBandC:ProgramDataABBto ensure write access is restricted strictly to local Administrators. - Cryptographically Sign Project Archives: Enforce organizational security policies requiring all
.pcmpproject files shared across substations to be cryptographically signed by authorized lead protection engineers before import.



