CVE-2026-54801
SICAM: Unverified Password Change (CVE-2026-54801)
Affected
- Siemens/SICAM
range_unparsed *..8 Products <V26.20
Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
8 Products <V26.20Metrics
Show all metrics
Weakness classes (CWE)
CWE-620Base
Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-09 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-54801","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…