← All Advisories

CVE-2026-9854

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9854

Key Details

CVECVE-2026-9854
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-09
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsHitachi Energy microscada_x_sys600 and Hitachi Energy MicroSCADA SYS600
Classified asCWE-303 (Incorrect Implementation of Authentication Algorithm)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi Energymicroscada_x_sys600
Hitachi EnergyMicroSCADA SYS600
SubsystemsGeneral OT
SectorsMultiple

What to Know

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

What to Do

Monitor Hitachi Energy's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9854
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9854
Vendor advisoryhttps://publisher.hitachienergy.com/preview?DocumentID=8DBD000249&LanguageCode=en&DocumentPartId=&Action=Launch