Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-107194: Sungrow iSolarCloud allows login without proper password

CVE-2026-107194 · published 3 days ago
Summary

The online portal used by Sungrow iSolarCloud can be tricked into accepting a fake login request, letting an attacker take over any user account. This could let someone control solar power systems and possibly cause local power outages. Install the latest software update from Sungrow and review account access logs for any suspicious activity.

What to do
  • Update sungrow isolarcloud to version 2026 or later.
Affected software
VendorProductAffected versions
sungrow isolarcloud < 2026
Original advisory text
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe....
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-288Authentication Bypass Using Alternate Path
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-107194 · MITRE
Track software like this
Free during beta