mySCADA myPRO Manager: Two Missing-Authorization Flaws in an ICS Management Platform (Control Network Focus)
What the mySCADA myPRO Manager Authorization Flaws Mean for Control Networks Vulnerability overview mySCADA myPRO Manager carries two missing-authorization vulnerabilities, CVE-2026-73807 (CVSS 9.8) and CVE-2026-82567 (CVSS 6.3), according to a CISA advisory. mySCADA Technologies fixed both in version 2.2. No public exploitation has been reported. Mechanism and exploitation conditions…
The mySCADA myPRO Manager platform has been identified as having two missing-authorization vulnerabilities, CVE-2026-73807 and CVE-2026-82567, according to a CISA advisory. The vulnerabilities allow unauthenticated access to management functions, enabling an attacker to change how the control system reports and potentially disrupt its operations.
Version 2.2 of the software resolves the issues, with no public exploitation reported. The vulnerabilities exist due to insufficient authentication checks on the command API and notification gateway endpoints. These flaws can be exploited without credentials, provided there is network access to the relevant service. The only requirement is that the attacker can reach the service, which is often a matter of accessing the same VLAN as the affected system.
The impact of these vulnerabilities can be significant for operators in manufacturing, energy, water, or transportation sectors, as it results in lost visibility and potential process disruption. The SMS gateway also provides an internal-looking channel, making the messages more convincing than an external phishing attempt. The affected products are versions 2.1 and earlier of mySCADA myPRO Manager, with version 2.2 resolving the issues.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.