CVE-2026-26289: Subnet Solutions Powersystem Center 2020
High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.
Affected products
- Subnet Solutions Powersystem Center 2020: from 5.8, before 5.29 (fixed in 5.29)
- Subnet Solutions Powersystem Center 2024: from 6.0, before 6.2 (fixed in 6.2)
- Subnet Solutions Powersystem Center 2026: from 7.0, before 7.1 (fixed in 7.1)
Published 2026-05-12. Last modified 2026-06-17.