Junglewise Threat Intelligence

CVE-2026-9853: Hitachi Energy SYS600 unauthorized access to application objects

CVE-2026-9853 · Severity: high · CVSS 7.8 · Published 2026-09-03

Technologies: Hitachienergy Microscada X Sys600, Hitachi Energy SYS600. Vendors: Hitachienergy, Hitachi Energy.

Executive brief

SYS600 is a power system management application used by utilities to control and monitor electrical infrastructure. A vulnerability allows any user with operating system access to the server to view and modify critical application data without needing legitimate SYS600 credentials, potentially enabling unauthorized changes to power system configurations or data theft.

Technical details

The vulnerability is an authentication bypass flaw in SYS600 that permits OS-level access to the server to escalate into application-level access. An attacker with local system access (such as through compromised credentials or direct server access) can read and modify application objects that should only be accessible to authenticated SYS600 users. The attack requires local/physical access to the server or prior compromise of OS-level credentials. No authentication to the SYS600 system itself is required once OS-level access is obtained. A patch is available as indicated by the published advisory.

Affected products

  • Hitachi Energy SYS600

Timeline

  • 2026-09-03: disclosed

References

Related threats