CVE-2026-9854
Received Received - Intake

Privilege Escalation in SYS600 RBAC Mechanism

Vulnerability report for CVE-2026-9854, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Hitachi Energy

Description

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the SYS600 RBAC mechanism. Users with access to engineering tools can escalate their privileges to administrator level on the underlying Windows host, gaining full control over the machine.

Impact Analysis

An attacker with engineering tool access could take complete control of the Windows host, allowing them to install malware, steal data, or disrupt operations.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or system compromise, violating compliance requirements for data protection and security controls in standards like GDPR and HIPAA.

Mitigation Strategies

Restrict access to engineering tools to only authorized personnel. Review and audit user privileges regularly to prevent privilege escalation. Disable unnecessary administrative access for users with engineering tool access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9854. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart