# CVE-2026-54801

## Summary

- **CVE ID:** CVE-2026-54801
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-620
- **Published:** Jul 9, 2026
- **Last Modified:** Jul 10, 2026

## Description

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.

## Affected Products

- Siemens — CPCI85 Central Processing/Communication (0)
- Siemens — SICORE Base system (0)

## References

- [CNA](https://cert-portal.siemens.com/productcert/html/ssa-229470.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.62%
- **EPSS Percentile:** 47.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._