Junglewise Threat Intelligence

CVE-2026-33570: Subnet Solutions PowerSYSTEM Center incorrect authorization in REST API

CVE-2026-33570 · Severity: medium · CVSS 5.7 · Published 2026-05-12

Technologies: Subnet Solutions Inc. PowerSYSTEM Center 2020. Vendors: Subnet Solutions Inc..

Executive brief

Subnet Solutions PowerSYSTEM Center, a management platform used in critical infrastructure and energy sectors, contains a security flaw in its web interface. An authorized user with low-level access can bypass intended restrictions to view sensitive device information that should only be available to higher-level operators. This could lead to the unauthorized exposure of operational data or system configurations.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the REST API endpoint for devices within Subnet Solutions PowerSYSTEM Center. The flaw allows an authenticated attacker with low-level privileges to bypass operational permission checks and retrieve sensitive device information. The attack vector is restricted to the adjacent network (AV:A), meaning the attacker must have access to the local or management network where the system resides. Successful exploitation results in a loss of confidentiality regarding device data. The issue is addressed in PowerSYSTEM Center 2020 Update 29, 2024 Update 2, and 2026 GA Hotfix.

Affected products

  • Subnet Solutions Inc. PowerSYSTEM Center 2020 >=5.11.x, <=5.28.x

Timeline

  • 2026-05-12: advisory: CISA ICSA-26-132-02 published
  • 2026-05-12: disclosed: CVE-2026-33570 published

References