CVE-2026-4436
GPL Odorizers GPL750 Missing Authentication for Critical Function
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
15th
A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.
| CWE | CWE-306 |
| Vendor | gpl odorizers |
| Product | gpl750 (xl4) |
| Published | Apr 9, 2026 |
| Last Updated | Apr 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for gpl odorizers gpl750 (xl4)
Be the first to know when new high vulnerabilities affecting gpl odorizers gpl750 (xl4) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
GPL Odorizers / GPL750 (XL4)
v1.0 < v6.0
GPL Odorizers / GPL750 (XL4 Prime)
v4.0 < v6.0
GPL Odorizers / GPL Odorizers GPL750 (XL7)
v13.0 < v20.0
GPL Odorizers / GPL Odorizers GPL750 (XL7 Prime)
v18.4 < v20.0
References
lincenergysystems-my.sharepoint.com: https://lincenergysystems-my.sharepoint.com/:f:/p/h_baer/IgDYaHIhXpyLQJvnKPd6b80TAUgV7Lp8qmVYBFUb0lmr7ak?e=JLeADm cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-099-02 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-099-02.json
Credits
An anonymous researcher reported this vulnerability to CISA.