← All Advisories

CVE-2026-7395

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-7395

Key Details

CVECVE-2026-7395
CVSS Score / Version8.5 (High) / CVSS v4.0
Updated2026-09-29
Affected productsHitachi Energy Asset Suite
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi EnergyAsset Suite
SubsystemsGeneral OT
SectorsMultiple

What to Know

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment. (NVD)

What to Do

Monitor Hitachi Energy's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-7395
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-7395