Summary
CVE-2026-11833 is a high-severity cleartext transmission vulnerability (CWE-319) affecting Yokogawa FAST/TOOLS and CI Server. The web server component may return HTTP responses that expose CI Server setting and configuration information to unauthenticated remote requesters — without requiring any credentials or user interaction. Yokogawa explicitly notes that this information "could be exploited by an attacker for other attacks," and the CVSS 4.0 score is 8.2 (HIGH).
Technical details
- Root cause: The affected web server transmits CI Server configuration data in cleartext HTTP responses, classified under CWE-319 (Cleartext Transmission of Sensitive Information). The server does not restrict access to this configuration data before responding to network requests.
- Trigger conditions: No authentication and no user interaction are required. A remote attacker can elicit the sensitive response by sending a crafted or ordinary HTTP request to the exposed web server component.
- Attack vector: Network-accessible (AV:N); low attack complexity (AC:L); no privileges required (PR:N); no user interaction (UI:N). An attack prerequisite (AT:P) exists, consistent with the need to reach the FAST/TOOLS web interface.
- Impact: High confidentiality impact on the vulnerable component (VC:H). Exposed CI Server settings may include system topology details and configuration parameters that an attacker can use as reconnaissance for deeper intrusion into operational technology (OT) or industrial control system (ICS) environments. No integrity or availability impact is reported.
Affected software
- Yokogawa FAST/TOOLS — Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB — Versions R9.01 through R10.04
- Yokogawa CI Server — All packages — Versions R1.01 through R1.04
Severity
CVSS 4.0 Base Score: 8.2 (HIGH)
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Note: Yokogawa published this vulnerability under CVSS 4.0. No CVSS 3.1 vector has been issued for this CVE.
Mitigation and recommended actions
- Immediate: Consult Yokogawa Security Advisory YSAR-26-0004 (published June 23, 2026) for vendor-specific patch guidance and remediation steps applicable to your installed version. Apply all available patches as directed by the advisory.
- Network mitigation: If immediate patching is not feasible, restrict network access to the FAST/TOOLS and CI Server web interface at the firewall or network perimeter level. FAST/TOOLS web components (HMIWEB, HMIMOB) should not be directly reachable from untrusted networks. Implement allowlist-based access controls to limit which hosts can reach ports serving the FAST/TOOLS web server (commonly TCP/8080).
- Monitoring: Review network logs for unexpected access to the FAST/TOOLS web server endpoints. Alert on unauthenticated HTTP requests returning configuration-class responses.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

