Sungrow iSolarCloud login flaw let anyone with a target's email address sign in without the password, including admin accounts able to stop inverters and push firmware; Australian region affected, fixed within a day
German security firm Jakkaru disclosed on 7 October 2026 a business-logic flaw in iSolarCloud, the cloud platform Sungrow uses to manage solar plants, inverters and battery storage. One value of the login_type field in the (encrypted and signed) login request made the service authenticate the account named in the request and ignore the password, so anyone who knew a user's email address could log in, with no email or other login alert to the owner, and could then use account recovery to keep control. Customer and administrative accounts share the same management environment, so Jakkaru says a compromised administrator account could view and change plants, start or stop inverters and batteries, see registered organisations and users (including large German solar installers), and install custom firmware on any cloud-connected device. iSolarCloud runs four regional systems, European, Chinese, Australian and international, and the flaw was in all of them. Jakkaru says Sungrow published a hotfix within a day of being told and began a root-cause review. No CVE has been published and no exploitation is reported. Sungrow is one of the largest inverter makers, with more than 1,000 GW of converters installed by Jakkaru's count, and is common on Australian rooftops. Primary: Jakkaru; wire: Cyber Security News.
- Product
- Sungrow iSolarCloud (cloud management for Sungrow inverters and batteries), all four regional instances including Australia
- Versions
- Cloud service; fixed server-side by Sungrow (no customer version to install)
- CVSS
- Not published (no CVE); researcher rates it critical
- Exploited in Australia?
- unknown
- Patch to
- No customer patch; Sungrow fixed the service. Owners and installers: review iSolarCloud account access and linked organisations, reset passwords and recovery details, and consider limiting inverter cloud connectivity to what you actually use.
Primary: Jakkaru — Sungrow vulnerability exposes gigawatts of power worldwide (7 Oct 2026) · Cyber Security News — Critical Sungrow inverter vulnerability lets attackers access solar plants without passwords (8 Oct 2026)
