Authentication Vulnerability in mySCADA myPRO Manager Product
CVE-2026-73807
9.3CRITICAL
What is CVE-2026-73807?
The mySCADA myPRO Manager command API is susceptible to an authentication bypass issue, allowing unauthenticated attackers with network access to exploit privileged management functions. This vulnerability raises significant security concerns, as it permits unauthorized individuals to manipulate critical system settings and potentially disrupt operations.
Affected Version(s)
mySCADA myPRO 0 <= 2.1
mySCADA myPRO 2.2
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SECNORA, Rajivarnan R. and Shirshak reported these vulnerabilities to CISA.
