๐Ÿ” CVE Alert

CVE-2026-82567

MEDIUM 6.3

mySCADA myPRO Manager Missing Authorization

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.

CWE CWE-862
Vendor myscada technologies
Product myscada mypro
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for myscada technologies myscada mypro

Be the first to know when new medium vulnerabilities affecting myscada technologies myscada mypro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

mySCADA Technologies / mySCADA myPRO
0 โ‰ค 2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
myscada.org: https://www.myscada.org/downloads/mySCADAPROManager/ cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-03.json

Credits

SECNORA, Rajivarnan R. and Shirshak reported these vulnerabilities to CISA.