{"id":"CVE-2026-7395","title":"Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise","summary":"Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specificall…","severity":"high","cvss":8.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-306"],"vendor":"Hitachi Energy","product":"Asset Suite","affected":["asset_suite >= 9.6.0 <= 9.9.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T10:17:12.203","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7395","references":[{"url":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000254&LanguageCode=en&DocumentPartId=&Action=Launch","label":"cybersecurity@hitachienergy.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-29T10:31:36.313Z","slug":"CVE-2026-7395","body":"## Overview\n\nAsset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}