CVE-2026-107194
CRITICAL
9,2
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via 'login_type':'5' in a login request, potentially leading to 'local blackouts on the whole continent' in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
288
Authentication Bypass Using an Alternate Path or Channel
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based
https://jakkaru.de/articles/sungrow-vulnerability-exposes-gigawatts-worldwide
https://www.sungrowpower.com/en/products/cloud-software/isolarcloud