# CVE-2026-22618

## Summary

- **CVE ID:** CVE-2026-22618
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N)
- **CWE:** CWE-358
- **Published:** Apr 16, 2026
- **Last Modified:** Apr 16, 2026

## Description

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download centre.

## Affected Products

- Eaton — IPP software (0)

## References

- [CNA](https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1025.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 14.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._