Hitachi Energy Asset Suite
Hitachi Energy Asset Suite 9.9.0 and earlier expose unauthenticated servlets that can leak data or disrupt availability.
CISA issued an advisory for unauthenticated servlet access in Hitachi Energy Asset Suite 9.9.0 and earlier, an energy-sector product. CVE-2026-7395 (CVSS 8.1) exposes HTTPPublishAdapterTestServlet, intended for non-production testing, allowing configuration-file upload that can disclose information and compromise integrity. CVE-2026-11796 (CVSS 4.3) exposes reload and cache-flush servlets that can cause denial of service. EDF reported the flaws. Hitachi Energy says to upgrade to 9.9.1 when available and disable the affected servlets. Exploitation is not reported.