CVE-2026-22618
published 2026-04-16CVE-2026-22618: A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute…
PriorityP434high7.1CVSS 3.1
AVNACLPRNUIRSUCLIHAN
EPSS
0.23%
14.1th percentile
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eaton | intelligent_power_protector | < 2.00 | 2.00 |
| eaton | ipp_software | < 2.0 | 2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9ghh-rh79-4vmr: A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribut
ghsa_unreviewed·2026-04-16
CVE-2026-22618 [MEDIUM] CWE-358 GHSA-9ghh-rh79-4vmr: A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribut
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.
VulDB
Eaton IPP Software up to 1.x HTTP Response Header security check
vuldb·2026-04-16·CVSS 5.9
CVE-2026-22618 [MEDIUM] Eaton IPP Software up to 1.x HTTP Response Header security check
A vulnerability identified as problematic has been detected in Eaton IPP Software up to 1.x. The affected element is an unknown function of the component HTTP Response Header Handler. Performing a manipulation results in security check for standard.
This vulnerability is identified as CVE-2026-22618. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-16
Published