# Hubbell Aclara Metrum flaw exposes energy grid devices

Published: 2026-06-23 · Severity: high · Sectors: energy
Canonical: https://vorant.io/reports/0235d5c7-6b46-5d6a-bc7b-5ea81b2cbc90/hubbell-aclara-metrum-flaw-exposes-energy-grid-devices

> A missing authentication vulnerability in Hubbell Aclara Metrum Cellular Web Interface allows unauthenticated attackers to alter critical device settings and disrupt communications in U.S. energy infrastructure.

CISA has disclosed CVE-2026-1840, an authentication bypass vulnerability in Hubbell Aclara Metrum Cellular Web Interface versions prior to v2.1.0.105. The flaw stems from missing authentication controls on critical system functions, allowing attackers to modify operational parameters and trigger system restarts without credentials. The vulnerability affects devices deployed in the U.S. energy sector and could enable persistent disruption of communications if exploited repeatedly.

The vulnerability is categorized as CWE-306 (Missing Authentication for Critical Function), exposing essential configuration settings to unauthorized manipulation. While no active exploitation has been reported to CISA, the vulnerability's location in critical infrastructure components warrants prompt attention. Hubbell has released firmware version 2.1.0.105 to address the issue and recommends users download the patch from their Aclara Connect portal.

CISA emphasizes standard ICS security practices including network segmentation, firewall protection, and restricting Internet exposure of affected devices. Organizations are advised to ensure control system devices remain isolated from business networks and to use secure remote access methods such as VPNs when necessary.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1840

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0235d5c7-6b46-5d6a-bc7b-5ea81b2cbc90/hubbell-aclara-metrum-flaw-exposes-energy-grid-devices.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
