Status: UPDATED | Advisory ID: CVE-2026-9854
| CVE | CVE-2026-9854 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-09 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Hitachi Energy microscada_x_sys600 and Hitachi Energy MicroSCADA SYS600 |
| Classified as | CWE-303 (Incorrect Implementation of Authentication Algorithm) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Hitachi Energy | microscada_x_sys600 | ||
| Hitachi Energy | MicroSCADA SYS600 |
| Subsystems | General OT |
| Sectors | Multiple |
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
Monitor Hitachi Energy's web page for any future patch releases. See vendor advisory link below.