CVE-2026-82567: mySCADA myPRO Manager Missing Authorization

Published Sep 15, 2026
·
Updated

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.

Affected Software

1 affected component
mySCADA myPRO Manager

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade mySCADA myPRO Manager to a version that resolves this vulnerability.

    Fixed in 2.2
  2. Compensating control

    Restrict network access to the myPRO Manager notification gateway’s unauthenticated HTTP endpoint used to send SMS messages through the connected GSM modem (e.g., block/limit inbound access at the network/firewall) until the gateway is upgraded.

Event History

Sep 15, 2026
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Organizations running mySCADA myPRO Manager with a notification gateway reachable over the network and connected to a GSM modem are exposed. An attacker does not need credentials, but does need network access to the gateway.

2

What can an attacker do with successful exploitation?

An attacker can submit a phone number and message to the unauthenticated HTTP endpoint and cause the connected GSM modem to send arbitrary SMS messages.

3

Is authentication required to exploit the endpoint?

No. The endpoint accepts requests and sends SMS messages without requiring authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203