CVE-2026-7310: Hitachi Energy Mach Hidraw
Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.
A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially crafted XML file which may lead to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system.
Affected products
- Hitachi Energy Mach Hidraw: from 9.0, before 9.22 (fixed in 9.22)
Published 2026-05-26. Last modified 2026-07-24.