Back to database
Schedule51Critical9.2VulnerabilityCVE-2026-107194No patch link observed

CVE-2026-107194 — Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "…

Published Oct 7, 2026, 02:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107194

Description

Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X
9.2

Critical severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

Present

Attack Requirements

PR

None

Privileges Required

UI

None

User Interaction

VC

Low

Confidentiality (Vulnerable System)

VI

High

Integrity (Vulnerable System)

VA

High

Availability (Vulnerable System)

SC

High

Confidentiality (Subsequent System)

SI

High

Integrity (Subsequent System)

SA

High

Availability (Subsequent System)