CVE-2026-9854 PUBLISHED

Assigner: Hitachi Energy
Reserved: 28.05.2026 Published: 03.09.2026 Updated: 03.09.2026

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Hitachi Energy
Product MicroSCADA SYS600
Versions Default: unaffected
  • affected from 10.0 to 10.7 (incl.)

References

Problem Types

  • CWE-303 Incorrect implementation of authentication algorithm CWE

Impacts

  • CAPEC-115 Authentication Bypass