Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.
Published: 2026-07-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Affected Siemens CPCI85 Central Processing/Communication and SICORE Base systems contain insufficient authentication validation for administrative account modifications processed through the web API. The CWE-620 weakness allows an attacker with existing valid credentials to bypass security checks and elevate their privileges, potentially granting full administrative control over the device.

Affected Systems

All versions of Siemens CPCI85 Central Processing/Communication and SICORE Base systems prior to V26.20 are affected. The vulnerability exists in any release before the specified version threshold.

Risk and Exploitability

The CVSS score of 8.6 classifies this flaw as high severity. The EPSS score is less than 1%, indicating a very low but non‑zero risk of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog. An attacker who has already authenticated can exploit the web API to modify administrative accounts and gain elevated privileges. Based on the description, it is inferred that the web API is reachable over the network, enabling remote exploitation when network access is granted.

Generated by OpenCVE AI on July 26, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Siemens firmware update that addresses this vulnerability when it becomes available.
  • Restrict access to the web API by employing network segmentation, firewalls, and access control lists so that only trusted hosts can reach the endpoint.
  • Enforce multi‑factor authentication for all administrative accounts to reduce the risk of credential compromise.
  • Implement monitoring of administrative actions to detect unauthorized account modifications quickly.

Generated by OpenCVE AI on July 26, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Authenticated Privilege Escalation via Web API in Siemens CPCI85 and SICORE Base Systems

Wed, 22 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Web API Authentication Validation Flaw Allowing Privilege Escalation in Siemens CPCI85 and SICORE Base

Thu, 16 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Web API Authentication Validation Flaw Allowing Privilege Escalation in Siemens CPCI85 and SICORE Base

Wed, 15 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Web API in Siemens CPCI85 and SICORE Base Systems

Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Web API in Siemens CPCI85 and SICORE Base Systems

Sun, 12 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Insufficient Authentication Validation in Siemens CPCI85 and SICORE Base Systems Enables Privilege Escalation via Web API

Fri, 10 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Insufficient Authentication Validation in Siemens CPCI85 and SICORE Base Systems Enables Privilege Escalation via Web API

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System
Vendors & Products Siemens
Siemens cpci85 Central Processing\/communication
Siemens sicore Base System

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Cpci85 Central Processing\/communication Sicore Base System
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-07-09T17:37:43.135Z

Reserved: 2026-06-16T07:47:12.274Z

Link: CVE-2026-54801

cve-icon Vulnrichment

Updated: 2026-07-09T17:37:39.245Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:30:04Z

Weaknesses
  • CWE-620

    Unverified Password Change