CVE-2026-73807
Last modified
CVE-2026-73807 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| mySCADA Technologies | mySCADA myPRO | <= 2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-73807?
How severe is CVE-2026-73807?
How do I fix CVE-2026-73807?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73786A vulnerability in the web-based management interface of CPP…7.5
- CVE-2026-73787A vulnerability in the CPPM web interface could allow an aut…7.2
- CVE-2026-73788A vulnerability in the ClearPass OnGuard agent could allow a…6.5
- CVE-2026-73789A vulnerability in the web-based management interface of CPP…5.3
- CVE-2026-7379Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 all…7.5
- CVE-2026-7380Improper neutralization of Script-Related HTML tags in a web…6.1
- CVE-2026-73809A cleartext transmission of sensitive information vulnerabil…7.5
- CVE-2026-7381Plack::Middleware::XSendfile versions through 1.0053 for Per…9.1
- CVE-2026-73812httpd function check_header/3 rejects duplicate Content-Leng…8.3
- CVE-2026-73819The affected Ebyte product's vendor configuration utility …9.8
- CVE-2026-7382Exposure of Sensitive Information to an Unauthorized Actor, …6.5
- CVE-2026-73827SOY Calendar contains a cross-site scripting vulnerability. …4.8
Are you affected by CVE-2026-73807?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
