Threat reportVulnerabilityTL-2026-3091
Critical Sungrow iSolarCloud Login Logic Flaw (CVE-2026-107194) Allows Password-less Account Takeover of Solar Plants
Critical Sungrow iSolarCloud Login Logic Flaw (TL-2026-3091), also tracked as iSolarCloud login_type authentication bypass, is a critical-severity software vulnerability scored CVSS 9.2, first published 2026-10-09. It has no confirmed attribution, affects Sungrow iSolarCloud, references 1 CVE (CVE-2026-107194), maps to 9 MITRE ATT&CK techniques (T0831, T0855, T0857), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 9.2/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-3091
- Threat ID
- TL-2026-3091
- Also known as
- iSolarCloud login_type authentication bypass
- Severity
- CRITICAL
- CVSS
- 9.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- energy, renewable-energy, critical-infrastructure, utilities
- Target regions
- Europe, china, australia, Global
- Detection rules
- 9
- Indicators of compromise
- 16
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in Critical Sungrow iSolarCloud Login Logic Flaw
Malware and tooling: Solar
How Critical Sungrow iSolarCloud Login Logic Flaw works
A business-logic flaw in the Sungrow iSolarCloud login process let a remote attacker authenticate as any account whose email was known by sending login_type=5 in the encrypted REST login request, causing the password field to be ignored. Administrator takeover could expose all plants, inverters and battery storage on a regional cloud server, including firmware installation. Sungrow reproduced the issue and deployed an emergency patch on 2026-08-25, one day after the report was triaged.
Researchers at the German security firm Jakkaru reviewed the iSolarCloud management platform, which Sungrow uses to manage solar plants, inverters and battery storage worldwide (Sungrow reported more than 1000 GW installed by December 2025). The login request is a POST to an encrypted REST API protected by application-layer asymmetric encryption, request signatures and custom headers. These controls were not broken; the flaw sits in the business logic inside the encrypted payload. At least eight distinct login_type values exist (0-7 tested, 8 tied to email-code login). Setting login_type to 5 made the platform log in as the account named in the user account field and ignore the password field (CWE-288, authentication bypass using an alternate path or channel).
The platform sent no email or other login alert when this method was used, so a takeover could go unnoticed. An attacker holding only a valid target email address could then use the account-recovery / password-reset functionality to hold the account longer term. Escalation to administrator was possible by traversing the organizational hierarchy to find administrator or parent-organization email addresses and replaying the bypass against them. A compromised administrator account on a regional instance (European, Chinese, Australian or international server) exposed all organizations, users and plants on that server, allowing viewing and modification of plants, starting and stopping inverter and battery systems, and installing custom firmware on connected devices. Known affected customers on the platform included the German distributors 1KOMMA5° and Enpal.
The issue was reported to Sungrow PSIRT on 2026-08-22. Sungrow reproduced it and deployed an emergency patch across all iSolarCloud levels on 2026-08-25, with the root cause fully resolved the same day. Jakkaru verified the fix in mid-September 2026 and published on 2026-10-06. Sungrow states its logs show no evidence of exploitation by anyone other than the reporting researcher, no customer data leaks, service interruptions or unauthorized manipulation, and that critical functions such as firmware updates and device control require additional protection such as password verification and two-factor authentication. Sungrow commissioned an independent assessment by NCC Group. The CVE record (published 2026-10-07, status awaiting analysis) lists a CVSS v4.0 score of 9.2. No public PoC code, network IOCs or in-the-wild exploitation were reported in the sources.
MITRE ATT&CK techniques used in TL-2026-3091
Impact
Impair Process Control
T0855 Unauthorized Command Message
Persistence
T0857 System Firmware; T1098 Account Manipulation
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Privilege Escalation
Defense Evasion
Discovery
Collection
Affected products and versions in Critical Sungrow iSolarCloud Login Logic Flaw
- Sungrow — iSolarCloud
Vulnerable versions: iSolarCloud before 2026 (per CVE record; cloud service, all regional instances)
Fixed in: Server-side hotfix deployed 2026-08-25
Remediation for Critical Sungrow iSolarCloud Login Logic Flaw
Patches
- Sungrow server-side emergency patch applied to all iSolarCloud levels on 2026-08-25
Immediate actions
- Confirm the Sungrow server-side hotfix (deployed 2026-08-25) is in effect; no customer-side patch is required
- Change iSolarCloud passwords and audit user accounts, organization hierarchy and administrator accounts
- Review iSolarCloud account activity for unexpected logins, password resets or recovery-email changes
Workarounds
- None published; the flaw was fixed in the cloud service
Longer-term hardening
- Enable multi-factor authentication on iSolarCloud accounts
- Limit cloud access and permissions to the functions each user needs
- Do not expose inverter interfaces directly to the public internet
CVEs associated with Critical Sungrow iSolarCloud Login Logic Flaw
Weaknesses (CWE) in Critical Sungrow iSolarCloud Login Logic Flaw
Timeline of Critical Sungrow iSolarCloud Login Logic Flaw
- Sungrow reported to have more than 1000 GW of converters installed worldwide, making iSolarCloud a high-value aggregation point
- Jakkaru published earlier critical findings on Sungrow microinverter MQTT communications
- Jakkaru reported the login_type authentication bypass to Sungrow PSIRT
- Sungrow reproduced the issue and deployed an emergency patch across all iSolarCloud levels; root cause fully resolved the same day
- Follow-up verification of the fix in mid-September 2026; Sungrow commissioned an independent NCC Group security assessment
- Jakkaru published full technical write-up of the vulnerability
- German BSI confirmed Sungrow closed the flaw via emergency patching and found no evidence of active exploitation.
- CVE-2026-107194 published (CWE-288, CVSS v4.0 9.2), status awaiting analysis
- pv magazine and Cyber Security News reported the flaw and Sungrow's statement that logs show no exploitation beyond the researcher
Update history for TL-2026-3091
- 2026-10-09 — Sungrow iSolarCloud Authentication Bypass via login_type=5 (CVE-2026-107194, Business Logic Flaw in REST API): What changed No field escalation. Severity (CRITICAL), CVSS 9.2, exploitability (NONE) and status (PATCHED) unchanged; the report is corroborating with modest added detail. New indicators (5) Behavioral indicators for the login_type=5 reque
Sources cited for Critical Sungrow iSolarCloud Login Logic Flaw
- Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants Without Passwords
- Sungrow Vulnerability Exposes Gigawatts of Power Worldwide (Jakkaru)
- Sungrow patches iSolarCloud vulnerability after security researchers gain access (pv magazine)
- Sungrow corrige una vulnerabilidad de iSolarCloud (pv magazine España)
- CVE-2026-107194: iSolarCloud Vulnerability (CVSS 9.2)
- CVE-2026-107194: CWE-288 Authentication Bypass in Sungrow iSolarCloud (OffSeq Radar)
- Sungrow Fixes iSolarCloud Authentication Bypass Flaw (IndexBox)
- Sungrow iSolarCloud product page
Detection coverage for TL-2026-3091
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3091 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.