CVE-2026-54801

SICAM: Unverified Password Change (CVE-2026-54801)

Affected

  • Siemens/SICAM range_unparsed *..8 Products <V26.20

Description

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

SiemensSICAM
8 Products <V26.20

Metrics

8.6
Source: nvd-v4
48.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-09 15:16 UTC
CWE-620

Weakness classes (CWE)

  • CWE-620Base

    Unverified Password Change

    When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-09 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-54801","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…