discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

NAVTOR NavBox

CISA warned that NAVTOR NavBox 4.16.1.20 has hard-coded credentials in its SOAP interface, which could let a local attacker access privileged methods.

Jun 4·cisa.gov·2 min read

Intelligence analysis by GPT-5.4 Mini

CISA issued an ICS advisory for NAVTOR NavBox after finding hard-coded credentials in the product’s Windows Communication Foundation SOAP implementation. If the SOAP feature is enabled, a local attacker could bypass the intended transfer workflow and use privileged methods to write or overwrite files in application-defined paths.

Why it matters

This matters because the flaw affects industrial control system software and could disrupt operations if abused. Even though CISA says it is not remotely exploitable, the combination of local access and file-write capability still raises operational risk for affected deployments.

CISA found a hidden passcode mistake in a ship software tool called NavBox. If someone already gets inside the computer, they could use that mistake like a master key and mess with files, which could break normal work.

Analysis

What CISA reported

CISA’s advisory covers NAVTOR NavBox version 4.16.1.20 and identifies CVE-2026-21404. The agency says the product contains hard-coded credentials in its Windows Communication Foundation, or SOAP, implementation. If SOAP functionality is enabled, a local attacker can extract those credentials and use them to bypass the intended transfer workflow.

Impact

According to the advisory, successful authentication to the SOAP interface grants access to privileged WCF methods. That access can allow an attacker to write or overwrite files within application-defined paths, which can disrupt operations. CISA rates the issue as medium severity under both CVSS 3.1 and CVSS 4.0.

Fix and exposure

NAVTOR has released a patch in April 2026, and CISA says version 4.17.2.6 and later includes the fix. The advisory also notes that users with an active NavBox connection will automatically stay up to date, so no user action is required in that case.

Mitigation guidance

CISA recommends minimizing network exposure for control system devices, placing control networks behind firewalls, and using VPNs when remote access is necessary. It also reminds organizations to assess operational impact before deploying defensive controls. CISA says it has no report of known public exploitation specifically targeting this vulnerability and notes that the issue is not remotely exploitable, but it still carries high attack complexity only after local access is obtained.

Key points

  • CISA issued advisory ICSA-26-155-01 for NAVTOR NavBox.
  • The flaw is CVE-2026-21404 and involves hard-coded credentials in SOAP.
  • A local attacker could use the issue to reach privileged methods and alter files.
  • NAVTOR says version 4.17.2.6 and later contains the fix.
  • CISA says there is no known public exploitation and the issue is not remotely exploitable.
The Upside

NAVTOR says it patched the issue in April 2026, and CISA says version 4.17.2.6 and later includes the fix. If organizations are on the updated version, the exposure should be reduced without extra work for systems with an active NavBox connection.

The Downside

Systems still running 4.16.1.20 could remain exposed if SOAP is enabled and local access is available. Because the flaw can allow file overwrite actions, abuse could interfere with operations even though it is not remotely exploitable.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecurityunited-statestechpolicy

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 4, 2026

Source

cisa.gov

Share

Topics

securityunited-statestechpolicy

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…