CVE-2026-65310

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
31/07/2026
Last modified:
31/07/2026

Description

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration<br /> of affected versions, exposes its data and configuration endpoint<br /> without any authentication and permissive CORS on every response. An<br /> unauthenticated attacker with network access can read live process<br /> values and server configuration.

References to Advisories, Solutions, and Tools