CVE-2026-65310
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
31/07/2026
Last modified:
31/07/2026
Description
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration<br />
of affected versions, exposes its data and configuration endpoint<br />
without any authentication and permissive CORS on every response. An<br />
unauthenticated attacker with network access can read live process<br />
values and server configuration.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



