CVE-2026-7395
Received Received - Intake

Asset Suite HTTPPublishAdapterTestServlet Configuration File Upload Vulnerability

Vulnerability report for CVE-2026-7395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Hitachi Energy

Description

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet, which is intended for testing in non-production environments. This access can lead to unauthorized configuration file uploads, potentially causing information disclosure and integrity compromise.

Detection Guidance

Check for unauthorized access to HTTPPublishAdapterTestServlet by monitoring HTTP requests to paths containing 'HTTPPublishAdapterTestServlet'. Look for unusual configuration file uploads or unexpected network traffic from external sources.

Impact Analysis

An attacker could exploit this to upload malicious configuration files, leading to unauthorized access, data leaks, or system modifications. This could disrupt operations or expose sensitive information.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized data access or modification, potentially breaching GDPR (data protection) or HIPAA (healthcare data privacy) if sensitive data is exposed or altered.

Mitigation Strategies

Remove or disable HTTPPublishAdapterTestServlet in production environments. Restrict network access to the servlet using firewalls or network segmentation. Review and audit configuration files for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7395. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart