CVE-2026-26289
Subnet Solutions PowerSYSTEM Center Incorrect Authorization
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:H/SA:H
Productos afectados
Subnet Solutions · PowerSYSTEM Center 2020Subnet Solutions · PowerSYSTEM Center 2024Subnet Solutions · PowerSYSTEM Center 2026¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →