{"id":"CVE-2026-9853","title":"A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.\n\nOnly the …","summary":"A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.\n\nOnly the …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-303"],"vendor":"hitachienergy","product":"microscada_x_sys600","affected":["microscada_x_sys600 >= 10.0, <= 10.8"],"published":"2026-09-03","updated":"2026-09-09","sourceUpdated":"2026-09-09T19:36:31.563","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9853","references":[{"url":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000249&LanguageCode=en&DocumentPartId=&Action=Launch","label":"cybersecurity@hitachienergy.com"}],"tags":["nvd"],"epss":0.00125,"epssPercentile":0.02583,"ingestedAt":"2026-09-09T20:21:14.799Z","slug":"CVE-2026-9853","body":"## Overview\n\nA vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.\n\nOnly the SYS600 system users should be permitted to view and modify application objects.\n\n## Affected\n\n- `microscada_x_sys600 >= 10.0, <= 10.8`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}