Unauthorized Access in SYS600 System by Hitachi Energy
CVE-2026-9853

8.5HIGH

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
3 September 2026

What is CVE-2026-9853?

A significant security issue exists within the SYS600 system that allows any user authenticated to the server hosting the application to access and alter application objects. This flaw bypasses SYS600's authentication requirements, enabling potential unauthorized modifications to sensitive application data. It is crucial that only authenticated users of the SYS600 system are permitted to view or modify these objects, highlighting the urgent need to address this vulnerability to protect application integrity and security.

Affected Version(s)

MicroSCADA SYS600 10.0 <= 10.8

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.