High severity8.2NVD Advisory· Published May 12, 2026· Updated May 13, 2026
CVE-2026-26289
CVE-2026-26289
Description
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
1- Subnet Solutions PowerSYSTEM CenterCISA Alerts