External risk intelligence

mySCADA myPRO Manager API Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-73807

The vulnerability affects a management API in industrial automation software. Such management interfaces are commonly deployed as network-accessible services to facilitate remote oversight and configuration, making them frequently reachable over a network in typical deployment scenarios.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the mySCADA myPRO Manager's command API allows unauthenticated attackers with network access to perform privileged management functions. This could potentially expose sensitive control system operations to unauthorized manipulation.

  • Unauthenticated access to critical management functions.
  • Confirms exposure of industrial control system APIs.
  • Assess relevance and potential impact to operations.

Attack Path

How an attacker could exploit the issue

An attacker on the network could access the mySCADA myPRO Manager command API without needing any credentials. This could allow them to perform privileged management actions on the system.

  • Network access and no authentication required.
  • Accessing the command API.
  • Unauthorized privileged actions.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access to the mySCADA myPRO Manager command API could exploit this vulnerability to access privileged management functions, potentially impacting system control and configuration.

  • System management functions and configuration.
  • Via unauthenticated network access to the API.
  • Unauthorized system control and access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in mySCADA myPRO Manager's command API requires immediate attention from teams managing industrial control systems and operational technology. The first step is to identify all instances of the affected software, determine their network accessibility and criticality to operations, and then locate the specific system owners responsible for remediation.

  • Ownership: OT, Platform, or Application teams.
  • Verify first: Network exposure and business criticality.
  • Action: Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is mySCADA myPRO Manager used for?

mySCADA myPRO Manager is a software platform utilized in industrial automation environments. It acts as a central control interface, providing tools for operators to oversee, manage, and configure industrial control systems. Because it coordinates critical process operations, it serves as a bridge between human administrators and the physical machinery or telemetry data it monitors.

What does CWE-862 mean for CVE-2026-73807?

CWE-862 refers to a 'Missing Authorization' weakness. In the context of CVE-2026-73807, it means the software fails to verify that a user has the proper permissions before allowing them to execute sensitive commands. While a system might expect a valid login to perform administrative tasks, this vulnerability allows the API to process requests without ever checking for an identity or credential, effectively bypassing the security gate.

How can an attacker trigger this vulnerability?

An attacker can trigger this flaw by sending network requests directly to the affected command API. Because the API lacks authentication checks, no specific pre-conditions like knowing a username or password are required. Note that this requires network reachability to the API; the vulnerability cannot be triggered by someone who lacks the necessary network path to communicate with the service.

Do I need to worry about my deployment?

If you manage instances of this software, you should evaluate your risk. Halo Surface Signal identifies this as a higher-interest issue because industrial management APIs are often intentionally placed on networks to enable remote oversight. If your instance is reachable over a network—especially if it is not restricted to a local, trusted segment—it is considered exposed and relevant to your security posture.

When should I start addressing this issue?

You should begin by locating all deployed instances of myPRO Manager in your environment to understand your total footprint. Prioritize these assets based on their network accessibility and their criticality to your operations. Once identified, coordinate with the system owners to review your network architecture and restrict unauthorized access to the command API while you prepare for further updates.

References