CVE-2026-9854
largeLocal Privilege Escalation in Hitachi Energy MicroSCADA X SYS600
CVE-2026-9854 is a privilege escalation flaw in the role-based access control (RBAC) mechanism of Hitachi Energy MicroSCADA X SYS600 (CWE-303). A user who is authorized to use the SCADA system's engineering tools can leverage that access to elevate their privileges to administrator level on the underlying Windows host. Successful exploitation grants the attacker full control over the host machine, beyond the SCADA application itself. Any organization running MicroSCADA X SYS600 on Windows where users have access to the engineering tools is affected. There is no known exploitation in the wild, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.1%, not in CISA KEV).
What to do: Check the Hitachi Energy security advisory (published by their CNA) for fixed MicroSCADA X SYS600 versions and apply the vendor patch as soon as it is available, since no specific version numbers are given here. In the meantime, restrict access to the engineering tools to trusted personnel, apply least-privilege on the underlying Windows hosts, and monitor for unexpected local administrator account or privilege changes. Utilities should inventory which SYS600 Windows hosts allow engineering-tool access, as only those are exposed to this local escalation path.
| Hitachi Energy MicroSCADA X SYS600 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.
- Vendors
- hitachienergy
- Products
- microscada x sys600
- Weakness
- CWE-303
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.