CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
References
Link Resource
https://www.andritz.com/
Configurations

No configuration.

History

31 Jul 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 09:16

Updated : 2026-07-31 17:16


NVD link : CVE-2026-65310

Mitre link : CVE-2026-65310

CVE.ORG link : CVE-2026-65310


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function

CWE-942

Permissive Cross-domain Policy with Untrusted Domains