{"id":"CVE-2026-73807","title":"The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions","summary":"The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-862"],"vendor":"mySCADA Technologies","product":"mySCADA myPRO","affected":["myscada_mypro <= 2.1"],"published":"2026-09-15","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:35:57.087","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73807","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-03.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.myscada.org/downloads/mySCADAPROManager/","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"epss":0.00651,"epssPercentile":0.49799,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-16T18:10:11.386973Z"},"ingestedAt":"2026-09-15T22:45:31.284Z","slug":"CVE-2026-73807","body":"## Overview\n\nThe mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}