Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass in Sungrow iSolarCloud Leading to Account Takeover |
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization. | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-07T13:54:45.211Z
Reserved: 2026-10-07T13:54:44.767Z
Link: CVE-2026-107194
No data.
Status : Awaiting Analysis
Published: 2026-10-07T14:17:09.203
Modified: 2026-10-07T14:47:21.140
Link: CVE-2026-107194
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:45:06Z
-
CWE-288
Authentication Bypass Using an Alternate Path or Channel