CVE-2026-107194
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
| CWE | CWE-288 |
| Vendor | sungrow |
| Product | isolarcloud |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sungrow isolarcloud
Be the first to know when new unknown vulnerabilities affecting sungrow isolarcloud are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Sungrow / iSolarCloud
0 < 2026