It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
Exploit
CVE-2026-41032
GHSA