Unauthenticated Access Vulnerability in Hitachi Energy Asset Suite
CVE-2026-7395

8.5HIGH

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
29 September 2026

What is CVE-2026-7395?

The vulnerability in Hitachi Energy's Asset Suite allows unauthenticated users to exploit the HTTPPublishAdapterTestServlet. This component, intended solely for testing in non-production environments, could enable unauthorized configuration file uploads. As a result, attackers can expose sensitive information and potentially compromise the integrity of the system, raising serious concerns for organizations relying on this software.

Affected Version(s)

Asset Suite 9.6.0 <= 9.9.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.