Home
HIGH: 8.4 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:H/SA:HHIGH: 8.2 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LDefault status
unaffected
5.8.x (custom)
affected
Default status
unaffected
6.0.x (custom)
affected
Default status
unaffected
7.0.x
affected
Description
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.
Problem types
CWE-863 Incorrect Authorization
Product status
5.8.x (custom)
6.0.x (custom)
7.0.x
Credits
Kelly Stich of Subnet Solutions Inc. reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-132-02
github.com/...p/csaf_files/OT/white/2026/icsa-26-132-02.json