CVE-2026-107194Critical· 9.2▾ MidnightSungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account p…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-19572Critical· 9.3A security vulnerability has been identified in FlexNet Publisher lmadmin
CVE-2026-39769High· 7.5Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39793High· 8.8Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-100518Medium· 5.3Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
CVE-2026-100261Medium· 5.4In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVE-2026-88828Medium· 5.4The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that acc…