Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-29T09:46:05.445Z

Reserved: 2026-04-29T09:45:34.109Z

Link: CVE-2026-7395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T10:17:12.203

Modified: 2026-09-29T10:17:12.203

Link: CVE-2026-7395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses