← All Advisories

Sungrow iSolarCloud login_type Authentication Bypass Enables Account Takeover on Solar Grid Infrastructure, with NVD Citing Potential for Europe-Wide Outages

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-107194

Key Details

CVECVE-2026-107194
CVSS Score / Version9.2 (Critical) / CVSS v4.0
Updated2026-10-07
Affected productsSungrow iSolarCloud
Classified asCWE-288 (Authentication Bypass Using an Alternate Path or Channel)
Exploitation prediction (EPSS)0.34% probability of exploitation in the next 30 days (26% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
SungrowiSolarCloud
SubsystemsGeneral OT
SectorsMultiple

What to Know

Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization. (NVD)

What to Do

Monitor Sungrow's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-107194
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-107194