CVE-2026-54801 Details
Description
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.
A vulnerability exists in Siemens SICAM 8 products, specifically in the CPCI85 Central Processing/Communication application and the SICORE Base system, all versions prior to the respective V26.20 releases. The issue stems from inadequate validation of authentication credentials when administrative account changes are made via the web API. This flaw could enable an authenticated attacker to circumvent security measures and obtain unauthorized elevated privileges.
Users are advised to update to Siemens SICAM CPCI85 V26.20 or later, and SICORE V26.20.0 or later. The V26.20 update for CPCI85 is available within the 'CP-8031/CP-8050 Package' and the 'SICAM EGS Package'. For SICORE, the V26.20.0 update can be found in the 'CP-8010/CP-8012 Package' and the 'SICAM S8000 Package'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-229470.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-620 | Unverified Password Change | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |