Junglewise Threat Intelligence

CVE-2026-9854: Hitachi Energy SYS600 privilege escalation in RBAC mechanism

CVE-2026-9854 · Severity: high · CVSS 7.8 · Published 2026-09-03

Technologies: Hitachienergy Microscada X Sys600, Hitachi Energy SYS600. Vendors: Hitachienergy, Hitachi Energy.

Executive brief

SYS600 is a control system platform used in industrial and energy infrastructure. Users with access to engineering tools can escalate their privileges to administrator level, gaining complete control over the underlying Windows host and potentially disrupting critical operations or accessing sensitive system data.

Technical details

This vulnerability is a privilege escalation flaw in the role-based access control (RBAC) mechanism of SYS600. Users with legitimate access to engineering tools can bypass RBAC restrictions and escalate to administrator privileges on the Windows host. The attack is local in nature and requires the attacker to already have user access to the system. Successful exploitation grants full administrative control, allowing an insider or authenticated attacker to compromise system integrity, availability, and confidentiality. Patch availability and mitigation details should be verified from the vendor's official security advisory.

Affected products

  • Hitachi Energy SYS600

Timeline

  • 2026-09-03: disclosed

References

Related threats