Executive brief
mySCADA myPRO Manager is an industrial control system management platform deployed across critical infrastructure sectors worldwide. This vulnerability allows an unauthenticated attacker with network access to bypass authentication and access privileged management functions, potentially enabling complete control over critical infrastructure systems without any credentials.
Technical details
The vulnerability is a missing authentication enforcement issue (CWE-862) in the command API of mySCADA myPRO Manager versions ≤2.1. The API fails to properly enforce authentication on privileged functions, allowing an unauthenticated attacker with network access to invoke sensitive management operations. The attack requires only network reachability to the API endpoint and no user interaction. An attacker can directly call privileged management functions to manipulate industrial control system configuration, parameters, and operations. mySCADA Technologies released version 2.2 with authentication controls implemented.
Affected products
- mySCADA Technologies myPRO Manager ≤2.1
Timeline
- 2026-09-15: disclosed: CISA advisory ICSA-26-258-03 published
- 2026-09-15: patched: Version 2.2 released with fix