CVE-2026-65311: CWE-306 Missing authentication for critical function in ANDRITZ HIPASE-250
ANDRITZ HIPASE-250 contains an unauthenticated HTTP endpoint that allows remote attackers to change the server's logging level and target. This vulnerability can be exploited to suppress audit logging, potentially hiding malicious activity. No authentication is required to access this critical function. The vulnerability has a medium severity score of 5.3 and does not impact confidentiality or availability but affects integrity by allowing log tampering. No patch or official remediation information is currently available.
AI Analysis
Technical Summary
The HTTP server component of ANDRITZ HIPASE-250 exposes an undocumented endpoint that permits changing the server's logging level and target without authentication. This missing authentication (CWE-306) enables a remote attacker with network access to suppress audit logs, which may conceal other malicious activities on the system. The vulnerability is identified as CVE-2026-65311 with a CVSS 3.1 base score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). There is no known patch or remediation level provided by the vendor, and no known exploits in the wild have been reported.
Potential Impact
An unauthenticated remote attacker can suppress audit logging by changing the logging configuration, potentially concealing unauthorized or malicious activities. This impacts the integrity of the system's audit logs but does not affect confidentiality or availability. The ability to tamper with logs can hinder incident detection and response.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the HTTP server component to trusted users only to reduce exposure. Monitor for unusual changes in logging behavior if possible.
CVE-2026-65311: CWE-306 Missing authentication for critical function in ANDRITZ HIPASE-250
Description
ANDRITZ HIPASE-250 contains an unauthenticated HTTP endpoint that allows remote attackers to change the server's logging level and target. This vulnerability can be exploited to suppress audit logging, potentially hiding malicious activity. No authentication is required to access this critical function. The vulnerability has a medium severity score of 5.3 and does not impact confidentiality or availability but affects integrity by allowing log tampering. No patch or official remediation information is currently available.
CVSS v3.1
Score 5.3medium
Affected software
ANDRITZ
HIPASE-250
ANDRITZ
250 SCALA
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The HTTP server component of ANDRITZ HIPASE-250 exposes an undocumented endpoint that permits changing the server's logging level and target without authentication. This missing authentication (CWE-306) enables a remote attacker with network access to suppress audit logs, which may conceal other malicious activities on the system. The vulnerability is identified as CVE-2026-65311 with a CVSS 3.1 base score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). There is no known patch or remediation level provided by the vendor, and no known exploits in the wild have been reported.
Potential Impact
An unauthenticated remote attacker can suppress audit logging by changing the logging configuration, potentially concealing unauthorized or malicious activities. This impacts the integrity of the system's audit logs but does not affect confidentiality or availability. The ability to tamper with logs can hinder incident detection and response.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the HTTP server component to trusted users only to reduce exposure. Monitor for unusual changes in logging behavior if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CyberDanube
- Date Reserved
- 2026-07-21T20:33:52.962Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a6c5b5c9c2644c7f88b03e2
Added to database: 07/31/2026, 08:22:52 UTC
Last enriched: 08/07/2026, 14:46:52 UTC
Last updated: 09/12/2026, 10:01:32 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.