PT-2026-40435 · Unknown · Powersystem Center

Kelly Stich

·

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-26289

CVSS v3.1

8.2

High

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions PowerSYSTEM Center (affected versions not specified)
Description A REST API endpoint used for device account export allows an authenticated user with limited permissions to expose sensitive information that is normally restricted to administrative permissions only.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-26289

Affected Products

Powersystem Center