Home

Description

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.

PUBLISHED Reserved 2026-04-16 | Published 2026-05-12 | Updated 2026-05-13 | Assigner icscert




HIGH: 8.4CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:H/SA:H

HIGH: 8.2CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

5.8.x (custom)
affected

Default status
unaffected

6.0.x (custom)
affected

Default status
unaffected

7.0.x
affected

Credits

Kelly Stich of Subnet Solutions Inc. reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-26-132-02

github.com/...p/csaf_files/OT/white/2026/icsa-26-132-02.json

cve.org (CVE-2026-26289)

nvd.nist.gov (CVE-2026-26289)

Download JSON