# CVE-2026-73807

## Summary

- **CVE ID:** CVE-2026-73807
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-862
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 16, 2026

## Description

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

## Affected Products

- mySCADA Technologies — mySCADA myPRO (0)
- mySCADA Technologies — mySCADA myPRO (2.2)

## References

- [CNA](https://www.myscada.org/downloads/mySCADAPROManager/)
- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03)
- [CNA](https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-03.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.65%
- **EPSS Percentile:** 49.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._