Authentication and Authorization Vulnerabilities in mySCADA myPRO Manager
Multiple vulnerabilities in mySCADA myPRO Manager versions 2.1 and earlier allow unauthenticated attackers to execute arbitrary management commands or send unauthorized SMS messages.
mySCADA Technologies has disclosed two critical vulnerabilities in its myPRO Manager software, versions 2.1 and earlier. These vulnerabilities, tracked as CVE-2026-73807 and CVE-2026-82567, expose the management API and notification gateway to unauthenticated network access. CVE-2026-73807 (CWE-862) allows an unauthenticated attacker to invoke privileged management functions within the command API. CVE-2026-82567 (CWE-306) exposes an unauthenticated HTTP endpoint in the notification gateway that permits sending arbitrary SMS messages through a connected GSM modem. These flaws affect critical infrastructure sectors including Energy, Transportation, and Water management. Defenders should prioritize updating to version 2.2 and restricting network access to these interfaces to prevent unauthorized control or messaging.
Impact
Successful exploitation could lead to full unauthorized access to system management functions or the abuse of communication channels (GSM modems) to send unauthorized SMS messages. These vulnerabilities affect organizations across critical infrastructure sectors such as Energy, Food and Agriculture, and Water and Wastewater, posing risks to operational continuity and system integrity if accessed by malicious actors.
Recommendation
- Upgrade mySCADA myPRO Manager to version 2.2 or later immediately to patch CVE-2026-73807 and CVE-2026-82567.
- Isolate the myPRO Manager notification gateway and command API from public internet access by placing them behind firewalls or VPNs.
- Restrict network access to the management interfaces to authorized management workstations only.
Immediate actions
Upgrade mySCADA myPRO Manager to version 2.2
Mitigations
Restrict network access to myPRO Manager management interfaces
CVE-2026-73807