CVE-2026-9854
SYS600 Privilege Escalation Vulnerability
Description
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
INFO
Published Date :
Sept. 3, 2026, 7:55 a.m.
Last Modified :
Sept. 3, 2026, 7:55 a.m.
Remotely Exploit :
No
Source :
Hitachi Energy
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 4.0 | HIGH | e383dce4-0c27-4495-91c4-0db157728d17 |
Solution
- Apply vendor patches for SYS600.
- Review and restrict engineering tool access.
- Enforce strict Role-Based Access Control.
- Monitor host for unauthorized access.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-9854 vulnerability anywhere in the article.