CVE-2026-9853CWE-303

CVE-2026-9853

published September 3, 2026

CVSS
8.5
EPSS
0%
Percentile
2.3
In the wild
Unconfirmed
What it is

A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.

Only the SYS600 system users should be permitted to view and modify application objects.

The record
Technical detail
CVSS
8.5 · NONE
CVSS v4.0
8.5 · CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00122 · 2.3th percentile
Weakness
CWE-303 · Incorrect Implementation of Authentication Algorithm
Published
2026-09-03T17:06Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:45Z
    EPSS moved — → 0%
    epss
  • 03 SEP 07:53Z
    A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify…
    cvelistv5