Status: UPDATED
| Advisory ID: CVE-2026-107194
Key Details
| CVE | CVE-2026-107194 |
| CVSS Score / Version | 9.2 (Critical) / CVSS v4.0 |
| Updated | 2026-10-07 |
| Affected products | Sungrow iSolarCloud |
| Classified as | CWE-288 (Authentication Bypass Using an Alternate Path or Channel) |
| Exploitation prediction (EPSS) | 0.34% probability of exploitation in the next 30 days (26% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization. (NVD)
What to Do
Monitor Sungrow's web page for any future patch releases.
References