Vulnerability record

CVE-2026-11796

Severity: ElevatedExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-11796 scored CVSS 5.1

    Basis: NIST National Vulnerability Database

  2. Disclosed

    Hitachi Energy Asset Suite

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

Severity: HighAction: Mitigate

Hitachi Energy Asset Suite

Mitigate

No complete fix is indicated yet.

References

  • publisher.hitachienergy.com https://publisher.hitachienergy.com/preview?DocumentID=8DBD000254&LanguageCode=en&DocumentPartId=&Action=Launc…