Executive brief
Subnet Solutions PowerSYSTEM Center, a management platform used in the energy and manufacturing sectors, is affected by multiple security vulnerabilities. These flaws could allow an authorized user with low-level access to view sensitive administrative data, delete project groups, or manipulate email notifications. Exploitation could lead to unauthorized data exposure or disruption of critical infrastructure management operations.
Technical details
Subnet Solutions PowerSYSTEM Center is affected by several vulnerabilities including Incorrect Authorization (CWE-863) and CRLF Injection (CWE-93). Specifically, REST API endpoints for device account exports and device information fail to properly enforce administrative permissions, allowing low-privileged users to access restricted data. Additionally, a flaw in the device project groups feature allows unauthorized deletion of groups, and the email notification service is susceptible to CRLF injection when using SMTPS. These vulnerabilities are reachable via the adjacent network and require basic user authentication. Patches are available in PowerSYSTEM Center 2020 Update 29, 2024 Update 2, and 2026 GA Hotfix.
Affected products
- Subnet Solutions Inc. PowerSYSTEM Center 2020 <=5.28.x
- Subnet Solutions Inc. PowerSYSTEM Center 2024 >=6.0.x, <=6.1.x
- Subnet Solutions Inc. PowerSYSTEM Center 2026 7.0.x
CVE identifiers
- CVE-2026-35504
- CVE-2026-35555
- CVE-2026-26289
- CVE-2026-33570
Timeline
- 2026-05-12: advisory: CISA published advisory ICSA-26-132-02
- 2026-05-12: patched: Updates released for 2020, 2024, and 2026 versions