Executive brief
Subnet Solutions PowerSYSTEM Center, a management platform used in critical infrastructure and energy sectors, contains a security flaw in its web interface. An authorized user with low-level access can bypass intended restrictions to view sensitive device information that should only be available to higher-level operators. This could lead to the unauthorized exposure of operational data or system configurations.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the REST API endpoint for devices within Subnet Solutions PowerSYSTEM Center. The flaw allows an authenticated attacker with low-level privileges to bypass operational permission checks and retrieve sensitive device information. The attack vector is restricted to the adjacent network (AV:A), meaning the attacker must have access to the local or management network where the system resides. Successful exploitation results in a loss of confidentiality regarding device data. The issue is addressed in PowerSYSTEM Center 2020 Update 29, 2024 Update 2, and 2026 GA Hotfix.
Affected products
- Subnet Solutions Inc. PowerSYSTEM Center 2020 >=5.11.x, <=5.28.x
Timeline
- 2026-05-12: advisory: CISA ICSA-26-132-02 published
- 2026-05-12: disclosed: CVE-2026-33570 published