---
id: CVE-2026-73807
title: >-
  The mySCADA myPRO Manager command API does not properly enforce authentication
  for privileged functions
summary: >-
  The mySCADA myPRO Manager command API does not properly enforce authentication
  for privileged functions. An unauthenticated attacker with network access to
  the affected API could exploit this vulnerability to access privileged
  management…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: mySCADA Technologies
product: mySCADA myPRO
affected:
  - myscada_mypro <= 2.1
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:35:57.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73807'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.myscada.org/downloads/mySCADAPROManager/'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.00651
epssPercentile: 0.49833
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-16T18:10:11.386973Z'
ingestedAt: '2026-09-15T22:45:31.284Z'
---

## Overview

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
