---
id: CVE-2026-9853
title: >-
  A vulnerability exists in SYS600 which allows any user authenticated to the
  operating system of the server hosting the application to read and modify
  application objects without being authenticated to the SYS600 system itself.


  Only the …
summary: >-
  A vulnerability exists in SYS600 which allows any user authenticated to the
  operating system of the server hosting the application to read and modify
  application objects without being authenticated to the SYS600 system itself.


  Only the …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-303
vendor: hitachienergy
product: microscada_x_sys600
affected:
  - 'microscada_x_sys600 >= 10.0, <= 10.8'
published: '2026-09-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T19:36:31.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9853'
references:
  - url: >-
      https://publisher.hitachienergy.com/preview?DocumentID=8DBD000249&LanguageCode=en&DocumentPartId=&Action=Launch
    label: cybersecurity@hitachienergy.com
tags:
  - nvd
epss: 0.00125
epssPercentile: 0.0258
ingestedAt: '2026-09-09T20:21:14.799Z'
---

## Overview

A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.

Only the SYS600 system users should be permitted to view and modify application objects.

## Affected

- `microscada_x_sys600 >= 10.0, <= 10.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
