ZeroHour

CVE-2026-9854

large

Local Privilege Escalation in Hitachi Energy MicroSCADA X SYS600

CVSS 4.0
8.5 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-9854 is a privilege escalation flaw in the role-based access control (RBAC) mechanism of Hitachi Energy MicroSCADA X SYS600 (CWE-303). A user who is authorized to use the SCADA system's engineering tools can leverage that access to elevate their privileges to administrator level on the underlying Windows host. Successful exploitation grants the attacker full control over the host machine, beyond the SCADA application itself. Any organization running MicroSCADA X SYS600 on Windows where users have access to the engineering tools is affected. There is no known exploitation in the wild, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.1%, not in CISA KEV).

What to do: Check the Hitachi Energy security advisory (published by their CNA) for fixed MicroSCADA X SYS600 versions and apply the vendor patch as soon as it is available, since no specific version numbers are given here. In the meantime, restrict access to the engineering tools to trusted personnel, apply least-privilege on the underlying Windows hosts, and monitor for unexpected local administrator account or privilege changes. Utilities should inventory which SYS600 Windows hosts allow engineering-tool access, as only those are exposed to this local escalation path.

Affected
Hitachi Energy MicroSCADA X SYS600
Estimated exposure
largeon the order of tens of thousands of utility SCADA/control-room Windows hosts worldwide — Order-of-magnitude estimate based on the widely deployed installed base of MicroSCADA-family systems at electric utility control centers and substation engineering stations, of which only hosts with engineering-tool access are affected; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

Vendors
hitachienergy
Products
microscada x sys600
Weakness
CWE-303
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.