Sungrow has patched a serious security vulnerability that allowed attackers to access its iSolarCloud management platform without needing a valid password. The flaw, discovered by the security firm Jakkaru and disclosed on October 8, 2026, affected numerous solar plants and battery storage systems across Europe, China, Australia, and beyond. It posed a grave risk to both regular users and operators of large-scale solar installations.
What Went Wrong
The issue stemmed from a business logic error during the login process on iSolarCloud. While the platform used encrypted REST API requests, request signatures, and custom headers—standard protections—these did not prevent the vulnerability from existing. Researchers zeroed in on a parameter called login_type. By passing a specific value in this field, the system would authenticate the named user in the request while ignoring the password field altogether. In effect, anyone with a valid email address could log in without entering a password, and no notification or email alert was triggered when this method was exploited.
Compounding the danger, customer and administrative accounts share the same infrastructure. That means a malicious actor could exploit this loophole not only to gain basic account access but also escalate privileges—potentially assuming control of solar plants by modifying, stopping, or starting inverters and batteries, managing organizations, and even installing custom firmware on connected devices.
Scope, Response, & Recommendations
Sungrow, among the world’s largest makers of solar inverters, claimed over 870 gigawatts deployed globally as of June 2025, a number that has since been estimated to exceed 1,000 gigawatts. Because of this scale, a cloud security issue with iSolarCloud could lead to wide-reaching impact on energy systems. The affected platform provides remote access over solar assets—making any compromise particularly serious.
As soon as the flaw was reported, Sungrow’s product security team patched it within a day and commenced a thorough internal investigation to identify any associated weaknesses or root cause issues. However, the public disclosure has yet to include a CVE identifier, firmware versions impacted, or a customer-facing patch version.
Solar plant owners are advised to verify their iSolarCloud accounts and devices are running the latest updates. It’s critical to change passwords, enable multi-factor authentication if available, audit and limit administrative access, and remove outdated or unnecessary third-party users. Operators should also avoid exposing inverter dashboards and cloud management interfaces directly to the internet, and ensure clear separation between normal accounts and those with admin privileges.
In recent years, security researchers have flagged numerous risks in solar inverter ecosystems. Examples include issues with communication modules, insecure object references, and hard-coded credentials—all of which increase the attack surface for remote power generation control. The Sungrow vulnerability underscores how firmware updates, insecure remote access, and shared admin environments remain major vectors for potential disruption.
This vulnerability shows that even systems considered critical infrastructure can harbor basic logic flaws that escape standard protections. It highlights the importance of proactive cloud security hygiene—from secure API design to rigorous access control. What to watch: other inverter platforms for similar vulnerabilities, clear disclosures of affected firmware, and widespread adoption of MFA and alerting to ensure that even if breaches occur, detection can be rapid and mitigation effective.