CVE-2026-54801
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.62%
- CWE
- CWE-620
- Published
- 2026-07-09
- Last modified
- 2026-07-10
Affected products
- Siemens CPCI85 Central Processing/Communication
- Siemens SICORE Base system
Weakness type
Related vulnerabilities
- CVE-2026-86260 — sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change
- CVE-2026-85591 — phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
- CVE-2026-77644 — Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
- CVE-2026-76633 — WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenha
- CVE-2026-73292 — Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
- CVE-2026-17599 — Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
- CVE-2026-15964 — Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
- CVE-2026-12692 — Improper Authentication in Vimesoft's Enterprise Video Platform