PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-26289 Subnet Solutions CVE debrief

CVE-2026-26289 is an authorization issue in Subnet Solutions PowerSYSTEM Center's REST API device account export path. According to CISA, an authenticated user with limited permissions can expose sensitive information that should be restricted to administrative access. CISA published the advisory on 2026-05-12 and rates the issue High (CVSS 8.2) in the supplied record.

Vendor
Subnet Solutions
Product
PowerSYSTEM Center 2020
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-12
Advisory published
2026-05-12
Advisory updated
2026-05-12

Who should care

Organizations running PowerSYSTEM Center 2020, 2024, or 2026 should pay attention, especially OT/ICS administrators, security teams, and operators who delegate limited user access to the application or its REST API features.

Technical summary

The advisory states that a PowerSYSTEM Center REST API endpoint for device account export can be used by an authenticated user with limited permissions to access sensitive information normally restricted to administrators. The supplied advisory data lists affected product lines across PowerSYSTEM Center 2020, 2024, and 2026, and points to vendor fixes in PSC 2020 Update 29, PSC 2024 Update 2, and PSC 2026 GA Hotfix.

Defensive priority

High. This is a sensitive information disclosure issue in an industrial-control management product, and the access boundary involved is administrative versus limited-user permissions. Prioritize patching and review any accounts or workflows that can reach export-related API functions.

Recommended defensive actions

  • Update to the vendor-recommended fixed versions: PSC 2020 Update 29, PSC 2024 Update 2, or PSC 2026 GA Hotfix, as applicable to your deployment.
  • Review which users and service accounts can access export-related REST API functionality and remove unnecessary privileges where possible.
  • Monitor user activity records for unusual or bulk account export activity, and configure a notification rule to alert on bulk export events.
  • Follow the vendor's additional hardening guidance where applicable, including restricting access to Notification Settings to trusted administrators and monitoring 'Send from Address' and Activity Records.

Evidence notes

All technical claims here are drawn from the supplied CISA CSAF advisory ICSA-26-132-02 and its referenced CVE record. The advisory text specifically says the REST API device account export endpoint can expose sensitive information to an authenticated user with limited permissions. The supplied record also includes SSVCv2/E:N/A:N/2026-05-11T06:00:00.000000Z and lists the vendor remediation versions. No KEV entry or ransomware linkage is present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-26289 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-26289

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-26289 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-26289

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.