Threat reportVulnerabilityTL-2026-3091

Critical Sungrow iSolarCloud Login Logic Flaw (CVE-2026-107194) Allows Password-less Account Takeover of Solar Plants

criticalPATCHED

Critical Sungrow iSolarCloud Login Logic Flaw (TL-2026-3091), also tracked as iSolarCloud login_type authentication bypass, is a critical-severity software vulnerability scored CVSS 9.2, first published 2026-10-09. It has no confirmed attribution, affects Sungrow iSolarCloud, references 1 CVE (CVE-2026-107194), maps to 9 MITRE ATT&CK techniques (T0831, T0855, T0857), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.2/10Critical
CVEs
1Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-3091

Threat ID
TL-2026-3091
Also known as
iSolarCloud login_type authentication bypass
Severity
CRITICAL
CVSS
9.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
energy, renewable-energy, critical-infrastructure, utilities
Target regions
Europe, china, australia, Global
Detection rules
9
Indicators of compromise
16
Updates
2026-10-09 · revalidated 1× · latest source

Malware and tooling in Critical Sungrow iSolarCloud Login Logic Flaw

Malware and tooling: Solar

How Critical Sungrow iSolarCloud Login Logic Flaw works

A business-logic flaw in the Sungrow iSolarCloud login process let a remote attacker authenticate as any account whose email was known by sending login_type=5 in the encrypted REST login request, causing the password field to be ignored. Administrator takeover could expose all plants, inverters and battery storage on a regional cloud server, including firmware installation. Sungrow reproduced the issue and deployed an emergency patch on 2026-08-25, one day after the report was triaged.

Researchers at the German security firm Jakkaru reviewed the iSolarCloud management platform, which Sungrow uses to manage solar plants, inverters and battery storage worldwide (Sungrow reported more than 1000 GW installed by December 2025). The login request is a POST to an encrypted REST API protected by application-layer asymmetric encryption, request signatures and custom headers. These controls were not broken; the flaw sits in the business logic inside the encrypted payload. At least eight distinct login_type values exist (0-7 tested, 8 tied to email-code login). Setting login_type to 5 made the platform log in as the account named in the user account field and ignore the password field (CWE-288, authentication bypass using an alternate path or channel).

The platform sent no email or other login alert when this method was used, so a takeover could go unnoticed. An attacker holding only a valid target email address could then use the account-recovery / password-reset functionality to hold the account longer term. Escalation to administrator was possible by traversing the organizational hierarchy to find administrator or parent-organization email addresses and replaying the bypass against them. A compromised administrator account on a regional instance (European, Chinese, Australian or international server) exposed all organizations, users and plants on that server, allowing viewing and modification of plants, starting and stopping inverter and battery systems, and installing custom firmware on connected devices. Known affected customers on the platform included the German distributors 1KOMMA5° and Enpal.

The issue was reported to Sungrow PSIRT on 2026-08-22. Sungrow reproduced it and deployed an emergency patch across all iSolarCloud levels on 2026-08-25, with the root cause fully resolved the same day. Jakkaru verified the fix in mid-September 2026 and published on 2026-10-06. Sungrow states its logs show no evidence of exploitation by anyone other than the reporting researcher, no customer data leaks, service interruptions or unauthorized manipulation, and that critical functions such as firmware updates and device control require additional protection such as password verification and two-factor authentication. Sungrow commissioned an independent assessment by NCC Group. The CVE record (published 2026-10-07, status awaiting analysis) lists a CVSS v4.0 score of 9.2. No public PoC code, network IOCs or in-the-wild exploitation were reported in the sources.

MITRE ATT&CK techniques used in TL-2026-3091

Impact

T0831 Manipulation of Control

Impair Process Control

T0855 Unauthorized Command Message

Persistence

T0857 System Firmware; T1098 Account Manipulation

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Privilege Escalation

T1078 Valid Accounts

Defense Evasion

T1078.004 Cloud Accounts

Discovery

T1087.004 Cloud Account

Collection

T1213 Data from Information Repositories

Affected products and versions in Critical Sungrow iSolarCloud Login Logic Flaw

  • Sungrow — iSolarCloud
    Vulnerable versions: iSolarCloud before 2026 (per CVE record; cloud service, all regional instances)
    Fixed in: Server-side hotfix deployed 2026-08-25

Remediation for Critical Sungrow iSolarCloud Login Logic Flaw

Patches

  • Sungrow server-side emergency patch applied to all iSolarCloud levels on 2026-08-25

Immediate actions

  • Confirm the Sungrow server-side hotfix (deployed 2026-08-25) is in effect; no customer-side patch is required
  • Change iSolarCloud passwords and audit user accounts, organization hierarchy and administrator accounts
  • Review iSolarCloud account activity for unexpected logins, password resets or recovery-email changes

Workarounds

  • None published; the flaw was fixed in the cloud service

Longer-term hardening

  • Enable multi-factor authentication on iSolarCloud accounts
  • Limit cloud access and permissions to the functions each user needs
  • Do not expose inverter interfaces directly to the public internet

CVEs associated with Critical Sungrow iSolarCloud Login Logic Flaw

CVE-2026-107194

Weaknesses (CWE) in Critical Sungrow iSolarCloud Login Logic Flaw

CWE-288

Timeline of Critical Sungrow iSolarCloud Login Logic Flaw

  • Sungrow reported to have more than 1000 GW of converters installed worldwide, making iSolarCloud a high-value aggregation point
  • Jakkaru published earlier critical findings on Sungrow microinverter MQTT communications
  • Jakkaru reported the login_type authentication bypass to Sungrow PSIRT
  • Sungrow reproduced the issue and deployed an emergency patch across all iSolarCloud levels; root cause fully resolved the same day
  • Follow-up verification of the fix in mid-September 2026; Sungrow commissioned an independent NCC Group security assessment
  • Jakkaru published full technical write-up of the vulnerability
  • German BSI confirmed Sungrow closed the flaw via emergency patching and found no evidence of active exploitation.
  • CVE-2026-107194 published (CWE-288, CVSS v4.0 9.2), status awaiting analysis
  • pv magazine and Cyber Security News reported the flaw and Sungrow's statement that logs show no exploitation beyond the researcher

Update history for TL-2026-3091

Sources cited for Critical Sungrow iSolarCloud Login Logic Flaw

Detection coverage for TL-2026-3091

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3091 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats