---
id: CVE-2026-7395
title: >-
  Asset Suite allows unauthenticated users to access
  HTTPPublishAdapterTestServlet that can be used for configuration file upload,
  leading to information disclosure and integrity compromise
summary: >-
  Asset Suite allows unauthenticated users to access
  HTTPPublishAdapterTestServlet that can be used for configuration file upload,
  leading to information disclosure and integrity compromise. The
  HTTPPublishAdapterTestServlet is specificall…
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: Hitachi Energy
product: Asset Suite
affected:
  - asset_suite >= 9.6.0 <= 9.9.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:17:12.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7395'
references:
  - url: >-
      https://publisher.hitachienergy.com/preview?DocumentID=8DBD000254&LanguageCode=en&DocumentPartId=&Action=Launch
    label: cybersecurity@hitachienergy.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T10:31:36.313Z'
---

## Overview

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
