CVE-2026-54801: Siemens CPCI85 Central Processing/communication

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.

Affected products

  • Siemens CPCI85 Central Processing/communication: before V26.20 (fixed in V26.20)
  • Siemens Sicore Base System: before V26.20.0 (fixed in V26.20.0)

Published 2026-07-09. Last modified 2026-07-09.