CVE-2026-9854

HIGH

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting the...

Affects 0 products across 1 vendor.

CVSS 3.17.8
CVSS v48.5
EPSS0.1%
Percentile3th
PatchUnknown
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-303: CWE-303
Related Attack Patterns (CAPEC)
CAPEC-90 Reflection Attack in Authentication Protocol
via CWE-303

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A high severity vulnerability (CVE-2026-9854) affects the target system. A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-9854?
A high severity vulnerability (CVE-2026-9854) affects the target system. A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
What is the CVSS score for CVE-2026-9854?
CVE-2026-9854 has CVSS 7.8 (High). Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.1%.
Is CVE-2026-9854 actively exploited?
No confirmed active exploitation of CVE-2026-9854 as of 2026-09-10.
How do I remediate CVE-2026-9854?
Apply vendor patches for CVE-2026-9854. Monitor Hitachienergy advisories.
What systems are affected by CVE-2026-9854?
CVE-2026-9854 affects: Hitachienergy.
Vulnerability Details
CVE IDCVE-2026-9854
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2026-09-03
Last Modified2026-09-09
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Hitachienergy — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 25 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Hitachienergy
CVE-2024-2013 10.0 An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / ... CVE-2019-18253 10.0 An attacker could use specially crafted paths in a specific request to read o... CVE-2021-40342 9.8 In the DES implementation, the affected product versions use a default key f... CVE-2018-14805 9.8 ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP... CVE-2019-5620 9.8 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Mi...
View all Hitachienergy CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →