Vulnerability record

CVE-2026-7395

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-7395 scored CVSS 8.5

    Basis: NIST National Vulnerability Database

  2. Disclosed

    Hitachi Energy Asset Suite

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

Severity: HighAction: Mitigate

Hitachi Energy Asset Suite

Mitigate

No complete fix is indicated yet.

References

  • publisher.hitachienergy.com https://publisher.hitachienergy.com/preview?DocumentID=8DBD000254&LanguageCode=en&DocumentPartId=&Action=Launc…