CVE-2026-7695Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /SubstationWEBV2/main/elecMaxMinAvgValue. The manipulation of the argument fCircuitids leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-06-01)
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-05-03: 3Mentions · 2026-05-04: 1Mentions · 2026-06-01: 4Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-04: 1Technical Details · 2026-06-01: 405-0305-0406-01
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-033
Disclosure3
2026-05-041
Patch1
2026-06-014
Disclosure3General1
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources RedPacket Security - CVE-2026-7695 Alert OffSeq Threat Radar - CVE-2026-7695 VulDB - CVE-2026-7695 Details The Power Grid Just Became the Weak Link: Acrel EEMS SQL Injection Exposes Energy Operations to Unauthenticated Database Breach

    Post summary

    The text announces CVE‑2026‑7695, a SQL injection vulnerability in Acrel EEMS that can lead to unauthenticated database exposure, without providing PoC code, exploit tools, or patch details.

    10000128
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Acrel Electrical's EEMS (Enterprise Power Operation and Maintenance Cloud Platform) v1.3.0 is vulnerable to unauthenticated remote SQL injection via a single parameter in a publicly accessible endpoint. CVE-2026-7695 (CVSS 7.3) allows attackers to extract operational data,…

    Post summary

    The post announces an unauthenticated remote SQL injection in Acrel Electrical's EEMS v1.3.0 (CVE‑2026‑7695) with CVSS 7.3, allowing attackers to extract operational data.

    1000048
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 3, 2026, RedPacket Security disclosed CVE-2026-7695, a critical SQL injection vulnerability in Acrel Electrical's EEMS Enterprise Power Operation and Maintenance Cloud Platform v1.3.0. The flaw exists in an unknown function of the endpoint…

    Post summary

    RedPacket Security announced a critical SQL injection vulnerability (CVE-2026-7695) in Acrel Electrical’s EEMS v1.3.0, but no PoC, exploit code, or reports of active exploitation were provided.

    10000108
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. Acrel Electrical's EEMS (Enterprise Power Operation and Maintenance Cloud Platform) v1.3.0 contains a publicly disclosed, unauthenticated SQL injection (CVE-2026-7695, CVSS 7.3) in the…

    Post summary

    Acrel Electrical’s EEMS v1.3.0 has a publicly disclosed unauthenticated SQL injection (CVE‑2026‑7695, CVSS 7.3), but no PoC, exploit tool, active exploitation, or patch information is provided.

    1000047
    239 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7695 A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /S… https://www.cve.org/CVERecord?id=CVE-2026-7695

    Post summary

    The notice announces that CVE-2026-7695 has been identified in the Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0, citing an unknown function in a file and linking to the official CVE record.

    00010296
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Defenders must prioritize patching CVE-2026-7695 to secure critical infrastructure against easy exploitation. Unauthenticated access means attackers can manipulate power data directly. Full analysis: https://lyrie.ai/research/research/2026-05-04-acrel-eems-sqli-energy-grid

    Post summary

    The message urges defenders to patch CVE-2026-7695, highlighting that unauthenticated access could allow attackers to manipulate power data.

    0000032
    152 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7695 A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This affects an unknown function of the file /S… https://www.cve.org/CVERecord?id=CVE-2026-7695 ----- Traducción: CVE-2026-7695 Se … http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE‑2026‑7695 in Acrel's platform, referencing a CVE record, but offers no operational or technical details beyond the announcement.

    0000027
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7695 SQL Injection in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7695

    Post summary

    The post announces a new SQL injection vulnerability (CVE-2026-7695) in Acrel Electrical’s EEMS platform and links to a CVE details page, but offers no further exploitation or remediation information.

    0000051
    4.0K followersView on X

Explore more