Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-107194: Sungrow iSolarCloud allows login without proper password
CVE-2026-107194 · published 3 days ago
Summary
The online portal used by Sungrow iSolarCloud can be tricked into accepting a fake login request, letting an attacker take over any user account. This could let someone control solar power systems and possibly cause local power outages. Install the latest software update from Sungrow and review account access logs for any suspicious activity.
What to do
- Update sungrow isolarcloud to version 2026 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| sungrow | isolarcloud | < 2026 |
Original advisory text
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe....
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-288Authentication Bypass Using Alternate Path
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta