Path Traversal Vulnerability in Acrel Electrical EEMS Platform
CVE-2026-9550
Key Information:
- Vendor
Acrel Electrical
- Vendor
- CVE Published:
- 26 May 2026
Badges
What is CVE-2026-9550?
A security vulnerability has been identified within the Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Specifically, this flaw lies in an undisclosed functionality related to a file path manipulation in the application. By exploiting this path traversal issue, remote attackers can gain unauthorized access to sensitive files on the server. Notably, the exploit has been disclosed publicly, raising concerns about its potential for malicious use. Despite prior communication from security researchers, the vendor has not provided any response or patch, heightening the urgency for users to secure their installations.
Affected Version(s)
EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
