What was disclosed
CISA's republication is ICSA-26-279-03, a verbatim copy of Hitachi Energy PSIRT advisory 8DBD000254. The vendor's first release was September 29, 2026, and CISA's revision history shows the October 6 republication as revision 2. CISA says it is not responsible for the technical accuracy of republished advisories, and the notice says EDF reported the vulnerabilities to CISA. In that sense this is a vendor disclosure with CISA amplification, not independent research.
Both issues are classed as CWE-306, Missing Authentication for Critical Function. They involve different servlets and different impacts, so treat them as two separate problems.
| CVE-2026-7395 | CVE-2026-11796 | |
|---|---|---|
| Servlet(s) | HTTPPublishAdapterTestServlet | PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, ResourceBundleReloadServlet |
| Impact | Information disclosure and integrity compromise via configuration file upload | Denial of service affecting application availability |
| Intended environment | Testing, non-production | Production, depending on configuration |
| CVSS 3.1 (advisory) | 8.1 High | 4.3 Medium |
| CVSS 4.0 (advisory) | 8.5 High | 5.1 Medium |
Affected versions and the fix
The advisory lists Asset Suite 9.9.0 and earlier as affected. CVE-record mirrors give a narrower range: 9.6.0 through 9.9.0. Check which range applies to your installation instead of assuming older builds are covered the same way.
The vendor's fix is to update to Asset Suite 9.9.1 "when available." The advisory doesn't say 9.9.1 has shipped, so confirm availability with Hitachi Energy or your product provider before you plan a maintenance window.
The scores don't fully agree
The vendor advisory scores CVE-2026-7395 at 8.1 under CVSS 3.1, with user interaction required. Tenable's mirror of the CVE record lists a CVSS 3.1 score of 7.5 for it, with a different vector and no user interaction. For CVE-2026-11796, the vendor says 4.3 Medium and Tenable lists 7.5 High. The CVSS 4.0 scores match across sources: 8.5 and 5.1.
These differences probably come from how each source scored the vulnerability, but the source material doesn't explain them. For triage, rely on the CVSS 4.0 numbers, which agree, and on your own exposure. The availability flaw could rank higher than "Medium" suggests if your deployment depends on those production servlets.
Exploitation status
The advisory doesn't report exploitation in the wild. Third-party trackers that mirror the CVE record also don't mark CVE-2026-7395 as a known exploited vulnerability. Treat that as "none reported," not "none occurring." Servlets that are reachable without authentication tend to be easy to find with scanning, so don't wait for an exploitation report.
What administrators should do
- Inventory. Find every Asset Suite instance and record its version. Anything on 9.9.0 or earlier is in scope.
- Check exposure. Work out whether the named servlets are installed and reachable without authentication, and from which networks. Treat the test servlet separately from the production maintenance servlets.
- Disable the test servlet. The vendor says it is meant only for non-production use. Disable it wherever it exists in a production environment.
- Assess before disabling the maintenance servlets. The vendor says these servlets perform functions in production and that their utility there should be evaluated. Work out what depends on them before you turn them off.
- Get the details from the vendor. The advisory gives no endpoint paths, config file names or step-by-step disablement instructions. Ask Hitachi Energy support or your product provider rather than guessing at configuration changes.
- Plan the 9.9.1 upgrade. Do this once the vendor confirms availability.
- Cut network exposure in the meantime. CISA's guidance for these advisories is consistent:
- Keep control-system assets off the internet.
- Put them behind firewalls and isolate them from business networks.
- Use VPNs for remote access where it is required, keeping the VPN patched. CISA notes a VPN is only as secure as the devices connected to it.
- Run an impact analysis and risk assessment before deploying defensive measures.
- Report suspicious activity. If you see it, follow your internal incident procedures and report it to CISA.
Why this matters
A test servlet reachable in production is an old and recurring mistake. Debug and test endpoints get left behind, and they often skip the authentication that protects the rest of the application. The reload and flush servlets are a different problem: they are legitimate production features, but unauthenticated callers can trigger them. Any caller who can reach the application can, in principle, force cache flushes and reloads and disrupt it.
Asset Suite has appeared in several CISA advisories recently, including a January 2026 advisory for a Jasper Reports deserialization flaw rated CVSS v3 9.8 and a 2025 advisory covering multiple third-party component issues. For anyone running it, tracking Hitachi Energy PSIRT advisories is part of routine maintenance. Hitachi Energy's PSIRT page says it publishes advisories on a regular monthly schedule, on the last Tuesday of each month, with out-of-cycle releases for high risk.
What we don't know
- Whether Asset Suite 9.9.1 is available yet.
- Whether any instance is actually exposed without authentication. That depends on your configuration and network layout.
- How the CVSS 3.1 discrepancies arose.
- Whether anyone is exploiting these flaws.
Your own asset inventory and the vendor can answer the first two. The advisory doesn't resolve the other points.
References
- Hitachi Energy Asset Suite CISA · 2026-10-06T12:00:00+00:00
- Multiple Vulnerabilities in Hitachi Energy RTU500 Series | CISA cisa.gov
- CVE-2026-7395: CWE-306 Missing authentication for critical function in Hitachi Energy Asset Suite - Live Threat Intelligence - Threat Radar radar.offseq.com