Executive brief
Subnet Solutions PowerSYSTEM Center, a management platform used in the energy and manufacturing sectors, contains a security flaw in its project group management feature. An authenticated user with low-level permissions can delete device project groups that they should not have the authority to modify. This could lead to operational disruptions or the loss of organized configuration data within the system.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the device project groups feature of Subnet Solutions PowerSYSTEM Center. The flaw allows an authenticated attacker with limited permissions to bypass intended access controls and perform unauthorized deletions of project groups. The attack vector is restricted to the adjacent network (AV:A), and exploitation requires valid low-privilege credentials. Successful exploitation impacts system integrity and availability by allowing the removal of organizational data. Subnet Solutions has released updates (PSC 2024 Update 2 and PSC 2026 GA Hotfix) to address this issue.
Affected products
- Subnet Solutions Inc. PowerSYSTEM Center 2024 6.0.x - 6.1.x
- Subnet Solutions Inc. PowerSYSTEM Center 2026 7.0.x
Timeline
- 2026-05-12: advisory: CISA published ICSA-26-132-02
- 2026-05-12: disclosed: CVE-2026-35555 published to NVD