Home
HIGH: 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:NMEDIUM: 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:LDefault status
unaffected
6.0.x (custom)
affected
Default status
unaffected
7.0.x (custom)
affected
Description
PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
Problem types
CWE-863 Incorrect Authorization
Product status
6.0.x (custom)
7.0.x (custom)
Credits
Kelly Stich of Subnet Solutions Inc. reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-132-02
github.com/...p/csaf_files/OT/white/2026/icsa-26-132-02.json