CVE-2026-73807
9.8mySCADA Technologies · mySCADA myPRO
The mySCADA myPRO Manager command API fails to enforce authentication, allowing unauthenticated remote attackers to access privileged management functions.
Executive summary
A critical authentication bypass vulnerability in mySCADA myPRO allows unauthenticated attackers to gain full control over management functions, posing a severe risk to industrial control environments.
Vulnerability
This vulnerability is caused by an improper authorization check (CWE-862) within the Manager command API. It allows any unauthenticated attacker with network connectivity to the service to execute privileged commands without prior login.
Business impact
The ability for an unauthenticated actor to interact with privileged management APIs creates a high risk of unauthorized system configuration, data manipulation, or operational disruption. Given the CVSS score of 9.8, this flaw is categorized as critical because it provides a direct path for attackers to compromise the integrity and availability of industrial control systems.
Remediation
Immediate Action: Update the mySCADA myPRO Manager to version 2.2 or later immediately to resolve the authentication enforcement flaw.
Proactive Monitoring: Review system access logs for anomalous API requests or unauthorized command execution attempts originating from untrusted network segments.
Compensating Controls: Restrict network access to the mySCADA myPRO Manager interface via firewall rules, ensuring it is not exposed to the public internet or untrusted internal networks.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the critical nature of this vulnerability and the potential for severe impact on operational technology, organizations must prioritize upgrading to version 2.2. Apply the update as soon as possible and ensure that the management interface is isolated from non-essential network traffic to reduce the attack surface.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by SECNORA, Rajivarnan R. and Shirshak reported these vulnerabilities to CISA., per the CVE Program record.