Status: UPDATED
| Advisory ID: CVE-2026-7395
Key Details
| CVE | CVE-2026-7395 |
| CVSS Score / Version | 8.5 (High) / CVSS v4.0 |
| Updated | 2026-09-29 |
| Affected products | Hitachi Energy Asset Suite |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment. (NVD)
What to Do
Monitor Hitachi Energy's web page for any future patch releases.
References