CVE-2026-107194
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Sungrow iSolarCloud

Vulnerability report for CVE-2026-107194, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: MITRE

Description

Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Sungrow iSolarCloud 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107194 is an authentication bypass vulnerability in Sungrow's iSolarCloud platform. Attackers can manipulate the login request by setting 'login_type' to '5', bypassing authentication and gaining full administrative access without detection. This flaw affects all regional servers due to shared business logic and allows unauthorized users to take over solar plants, modify settings, install custom firmware, and access sensitive data.

Detection Guidance

Check login logs for unusual authentication attempts with login_type set to 5. Monitor network traffic for unauthorized administrative access to iSolarCloud servers. Inspect user accounts for unexpected privilege escalations or modifications.

Impact Analysis

This vulnerability could lead to unauthorized access to your solar energy system, allowing attackers to modify settings, install malicious firmware, or disrupt operations. For businesses or homeowners using iSolarCloud, it may cause system failures, data breaches, or even contribute to large-scale power outages. Users could experience financial losses, operational disruptions, or compromised personal data.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and security, such as GDPR and HIPAA, due to unauthorized access to sensitive data and potential data breaches. Organizations using iSolarCloud may face regulatory penalties, legal liabilities, and reputational damage for failing to protect user data and system integrity.

Mitigation Strategies

Apply the patch released by Sungrow immediately. Disable cloud connectivity for solar systems except during firmware updates. Separate user and administrative platforms to limit exposure. Review and restrict user privileges, especially for administrators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107194. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart