ICSA-25-317-04
·
Published 2026-06-23
·
View on CISA ICS-CERT ↗
Brightpick Mission Control / Internal Logic Control (Update A)
CVSS 7.4
HIGH
Risk Summary
Successful exploitation of these vulnerabilities could result in the exposure of sensitive information and the manipulation of critical functions by an attacker.
CVEs (3)
Remediations
- Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.
- For CVE-2025-64307: Brightpick has introduced a reverse-proxy authentication layer inline between the public load balancer and the internal service. This vendor fix has been applied to all deployed instances.
- Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.
Affected Vendors
Brightpick AI
Affected Products (1)
Brightpick AI
·
Brightpick Mission Control / Internal Logic Control
<1.67.0
Affected Sectors
Commercial Facilities, Critical Manufacturing, Healthcare and Public Health
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more