# CVE-2026-65310

## Summary

- **CVE ID:** CVE-2026-65310
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-306, CWE-942
- **Published:** Jul 31, 2026
- **Last Modified:** Jul 31, 2026

## Description

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network access can read live process
values and server configuration.

## Affected Products

- ANDRITZ — HIPASE-250 (0)
- ANDRITZ — HIPASE-250 (7.40)
- ANDRITZ — 250 SCALA (0)
- ANDRITZ — 250 SCALA (7.40)

## References

- [CNA](https://www.andritz.com/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._