# Critical Sungrow iSolarCloud Login Logic Flaw (CVE-2026-107194) Allows Password-less Account Takeover of Solar Plants

> A business-logic flaw in the Sungrow iSolarCloud login process let a remote attacker authenticate as any account whose email was known by sending login_type=5 in the encrypted REST login request, causing the password field to be ignored. Administrator takeover could expose all plants, inverters and battery storage on a regional cloud server, including firmware installation. Sungrow reproduced the issue and deployed an emergency patch on 2026-08-25, one day after the report was triaged.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T05:22:53.527Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3091
- **ID:** TL-2026-3091
- **Severity:** CRITICAL (CVSS 9.2)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-107194

## Description

Researchers at the German security firm Jakkaru reviewed the iSolarCloud management platform, which Sungrow uses to manage solar plants, inverters and battery storage worldwide (Sungrow reported more than 1000 GW installed by December 2025). The login request is a POST to an encrypted REST API protected by application-layer asymmetric encryption, request signatures and custom headers. These controls were not broken; the flaw sits in the business logic inside the encrypted payload. At least eight distinct login_type values exist (0-7 tested, 8 tied to email-code login). Setting login_type to 5 made the platform log in as the account named in the user account field and ignore the password field (CWE-288, authentication bypass using an alternate path or channel).

The platform sent no email or other login alert when this method was used, so a takeover could go unnoticed. An attacker holding only a valid target email address could then use the account-recovery / password-reset functionality to hold the account longer term. Escalation to administrator was possible by traversing the organizational hierarchy to find administrator or parent-organization email addresses and replaying the bypass against them. A compromised administrator account on a regional instance (European, Chinese, Australian or international server) exposed all organizations, users and plants on that server, allowing viewing and modification of plants, starting and stopping inverter and battery systems, and installing custom firmware on connected devices. Known affected customers on the platform included the German distributors 1KOMMA5° and Enpal.

The issue was reported to Sungrow PSIRT on 2026-08-22. Sungrow reproduced it and deployed an emergency patch across all iSolarCloud levels on 2026-08-25, with the root cause fully resolved the same day. Jakkaru verified the fix in mid-September 2026 and published on 2026-10-06. Sungrow states its logs show no evidence of exploitation by anyone other than the reporting researcher, no customer data leaks, service interruptions or unauthorized manipulation, and that critical functions such as firmware updates and device control require additional protection such as password verification and two-factor authentication. Sungrow commissioned an independent assessment by NCC Group. The CVE record (published 2026-10-07, status awaiting analysis) lists a CVSS v4.0 score of 9.2. No public PoC code, network IOCs or in-the-wild exploitation were reported in the sources.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1078.004 Cloud Accounts
- T1098 Account Manipulation
- T1078 Valid Accounts
- T1087.004 Cloud Account
- T1213 Data from Information Repositories
- T0855 Unauthorized Command Message
- T0831 Manipulation of Control
- T0857 System Firmware

## Sources

- [Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants Without Passwords](https://cybersecuritynews.com/sungrow-inverter-vulnerability/)
- [Sungrow Vulnerability Exposes Gigawatts of Power Worldwide (Jakkaru)](https://jakkaru.de/articles/sungrow-vulnerability-exposes-gigawatts-worldwide)
- [Sungrow patches iSolarCloud vulnerability after security researchers gain access (pv magazine)](http://www.pv-magazine.com/2026/10/08/sungrow-patches-isolarcloud-vulnerability-after-security-researchers-gain-access/)
- [Sungrow corrige una vulnerabilidad de iSolarCloud (pv magazine España)](http://www.pv-magazine.es/2026/10/08/sungrow-corrige-una-vulnerabilidad-de-isolarcloud-que-permitia-acceder-a-cuentas-sin-autenticacion/)
- [CVE-2026-107194: iSolarCloud Vulnerability (CVSS 9.2)](https://www.strix.ai/cve/CVE-2026-107194)
- [CVE-2026-107194: CWE-288 Authentication Bypass in Sungrow iSolarCloud (OffSeq Radar)](https://radar.offseq.com/threat/cve-2026-107194-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-sungrow-isolarcloud-7959e7c501a938e9)
- [Sungrow Fixes iSolarCloud Authentication Bypass Flaw (IndexBox)](https://www.indexbox.io/blog/sungrow-patches-critical-isolarcloud-authentication-bypass-vulnerability/)
- [Sungrow iSolarCloud product page](https://www.sungrowpower.com/en/products/cloud-software/isolarcloud)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3091
