Hitachi Energy Asset Suite
No complete fix is indicated yet.
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Developments from the last 30 days, newest first.
CVE-2026-7395 scored CVSS 8.5
Basis: NIST National Vulnerability Database
Hitachi Energy Asset Suite
Basis: CISA Cybersecurity Advisories (government advisory)
No complete fix is indicated yet.