Hitachi Energy's asset-management software for power utilities has two holes that do not require a password to walk through.
The vendor and CISA disclosed two vulnerabilities in Asset Suite, the inventory and maintenance-tracking software deployed at energy facilities worldwide. Version 9.9.0 and earlier ship with several servlets - diagnostic tools meant only for testing - that anyone on the network can reach without logging in. One, CVE-2026-7395, rated 8.1 on the CVSS scale, lets an attacker upload configuration files and compromise the system's integrity, while the other, CVE-2026-11796, covers four more servlets that can be abused to crash the application. French utility EDF found and reported both issues.
Asset Suite isn't a turbine controller; it's the database utilities use to track what hardware they own and when it needs maintenance. That makes this less dramatic than a grid-control bug, but it's a clean example of software shipping with test-only tools left reachable in production - and because it's energy infrastructure, the stakes sit a notch above a typical web app flaw. Hitachi Energy's actual fix, version 9.9.1, isn't out yet, so the advice for now is simply to turn the affected servlets off.
File it next to the long list of ICS advisories where the vulnerability wasn't clever code, but a debug switch nobody remembered to lock.