CVE-2026-9853 PUBLISHED

Assigner: Hitachi Energy
Reserved: 28.05.2026 Published: 03.09.2026 Updated: 03.09.2026

A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.

Only the SYS600 system users should be permitted to view and modify application objects.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Hitachi Energy
Product MicroSCADA SYS600
Versions Default: unaffected
  • affected from 10.0 to 10.8 (incl.)

References

Problem Types

  • CWE-303 Incorrect implementation of authentication algorithm CWE

Impacts

  • CAPEC-115 Authentication Bypass