CVE-2026-9853
Received Received - Intake

Authentication Bypass in SYS600 Application Objects

Vulnerability report for CVE-2026-9853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Hitachi Energy

Description

A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hitachienergy sys600 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SYS600 allows any authenticated operating system user to read and modify application objects without authenticating to the SYS600 system itself. This violates the intended access control where only SYS600 system users should have such permissions.

Impact Analysis

An attacker with OS access could read sensitive application data or modify critical system objects, leading to unauthorized data exposure, system manipulation, or potential service disruption. This could compromise confidentiality, integrity, and availability of the application.

Compliance Impact

This vulnerability likely violates data protection requirements in GDPR and HIPAA by enabling unauthorized access to sensitive data. It could result in non-compliance due to inadequate access controls and potential data breaches.

Mitigation Strategies

Restrict operating system user access to SYS600 application objects. Ensure only authorized SYS600 system users can view and modify application objects. Review and update user permissions to enforce least privilege principles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart