{"id":"CVE-2026-11796","title":"Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availabili…","summary":"Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availabili…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-306"],"vendor":"Hitachi Energy","product":"Asset Suite","affected":["asset_suite >= 9.6.0 <= 9.9.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T10:17:11.037","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-11796","references":[{"url":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000254&LanguageCode=en&DocumentPartId=&Action=Launch","label":"cybersecurity@hitachienergy.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-29T10:31:36.310Z","slug":"CVE-2026-11796","body":"## Overview\n\nAsset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}