CVE-2026-107194

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,2
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via 'login_type':'5' in a login request, potentially leading to 'local blackouts on the whole continent' in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.

288

Authentication Bypass Using an Alternate Path or Channel

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies: Not Technology-Specific, Web Based
View CWE Details
https://jakkaru.de/articles/sungrow-vulnerability-exposes-gigawatts-worldwide
https://www.sungrowpower.com/en/products/cloud-software/isolarcloud