Description
Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Published: 2026-09-29
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure and integrity compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows unauthenticated users to access an HTTPPublishAdapterTestServlet designed for testing, permitting arbitrary configuration file uploads. This flaw stems from an authentication bypass, enabling attackers to inject or replace configuration files, thereby exposing sensitive data and compromising the integrity of the system's settings.

Affected Systems

Hitachi Energy Asset Suite installations are affected. No specific version information is given, but any deployment exposing the HTTPPublishAdapterTestServlet, especially in a production environment, is vulnerable.

Risk and Exploitability

The CVSS score of 8.5 signals high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote unauthenticated access to the servlet over HTTP, inferred from the description.

Generated by OpenCVE AI on September 29, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that removes or restricts access to the HTTPPublishAdapterTestServlet for authenticated users only.
  • If no patch is available, delete the HTTPPublishAdapterTestServlet from the application to eliminate the upload capability.
  • Configure firewall or access control lists to limit network traffic to the servlet from only trusted IP ranges.

Generated by OpenCVE AI on September 29, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title HTTPPublishAdapterTestServlet File Upload Vulnerability
First Time appeared Hitachienergy
Hitachienergy asset Suite
Vendors & Products Hitachienergy
Hitachienergy asset Suite

Tue, 29 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hitachienergy Asset Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-29T15:03:46.600Z

Reserved: 2026-04-29T09:45:34.109Z

Link: CVE-2026-7395

cve-icon Vulnrichment

Updated: 2026-09-29T15:03:42.738Z

cve-icon NVD

Status : Received

Published: 2026-09-29T10:17:12.203

Modified: 2026-09-29T15:17:29.023

Link: CVE-2026-7395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:45:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function