CVE-2026-73807: mySCADA myPRO Manager Missing Authorization
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mySCADA myPRO Managerto a version that resolves this vulnerability.Fixed in 2.2 - Compensating control
Restrict network access to the mySCADA myPRO Manager command API so unauthenticated clients cannot reach privileged management functions.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with network access to the affected mySCADA myPRO Manager command API could exploit it. No prior credentials or user interaction are required.
What could an attacker gain through successful exploitation?
Successful exploitation could allow access to privileged management functions exposed by the command API.