Junglewise Threat Intelligence

CVE-2026-26289: Subnet Solutions PowerSYSTEM Center incorrect authorization in REST API

CVE-2026-26289 · Severity: high · CVSS 8.2 · Published 2026-05-12

Technologies: Subnet Solutions Inc. PowerSYSTEM Center 2024, Subnet Solutions Inc. PowerSYSTEM Center 2020, Subnet Solutions Inc. PowerSYSTEM Center 2026. Vendors: Subnet Solutions Inc..

Executive brief

Subnet Solutions PowerSYSTEM Center, a management platform used in critical infrastructure like energy and manufacturing, contains a security flaw in its device account export feature. This flaw allows a user with low-level access to export sensitive administrative information they should not be able to see. This could lead to unauthorized access to critical system accounts and potential disruption of industrial operations.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the REST API endpoint for device account export within Subnet Solutions PowerSYSTEM Center. The root cause is a failure to properly enforce administrative permission checks on the export function. An authenticated attacker with limited permissions can reach this endpoint via an adjacent network to expose sensitive information normally restricted to administrators. This vulnerability affects PowerSYSTEM Center 2020, 2024, and 2026 versions. Subnet Solutions has released updates (PSC 2020 Update 29, PSC 2024 Update 2, and PSC 2026 GA Hotfix) to remediate the issue.

Affected products

  • Subnet Solutions Inc. PowerSYSTEM Center 2020 >=5.8.x, <=5.28.x
  • Subnet Solutions Inc. PowerSYSTEM Center 2024 >=6.0.x, <=6.1.x
  • Subnet Solutions Inc. PowerSYSTEM Center 2026 7.0.x

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: CISA Advisory ICSA-26-132-02 published

References

Related threats