CVE-2026-11796
Received Received - Intake

Unauthenticated DoS Access in Asset Suite

Vulnerability report for CVE-2026-11796, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Hitachi Energy

Description

Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Asset Suite has unauthenticated access to servlets like PropertiesReloadServlet and CacheFlushServlet. These servlets can cause denial-of-service conditions by disrupting application availability, depending on how the application is configured.

Detection Guidance

Detect unauthorized access to servlets like PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, or ResourceBundleReloadServlet by monitoring network traffic for unusual requests to these endpoints. Check server logs for repeated access attempts to these paths.

Impact Analysis

An attacker could exploit this to crash or slow down the Asset Suite application, leading to downtime and reduced service availability for users.

Compliance Impact

The vulnerability allows unauthenticated users to access servlets that can cause denial-of-service conditions, potentially disrupting application availability. This could impact compliance with standards like GDPR or HIPAA by compromising data availability and integrity, though specific regulatory impacts depend on the application's configuration and environment.

Mitigation Strategies

Restrict access to the vulnerable servlets by implementing authentication and authorization controls. Disable or remove these servlets if they are not required for production use. Update Asset Suite to the latest version if a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11796. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart