The SolarEdge Monitoring Platform contains a cross-site request forgery vulnerability that could let an attacker hijack operator sessions and potentially gain unauthorized control over photovoltaic systems.
The flaw, reported by nu11secur1tyAI on April 26, 2026, lives in the /solaredge-web/p/initClient endpoint. The system allows session parameters to be generated and overwritten via POST requests that aren’t properly validated for origin. An attacker can force a legitimate operator’s browser to execute unauthorized commands without their knowledge.
There’s also an out-of-band injection angle. By manipulating the X-Forwarded-For and Referer headers, an attacker can force SolarEdge’s internal infrastructure to initiate requests to external, attacker-controlled domains. This points to a lack of framework-level input filtering.
The vulnerability has been classified as medium-to-high severity. An attacker who successfully exploits it could compromise operator sessions and gain control over physical solar energy infrastructure — not exactly the kind of thing you want exposed to the internet.
The vendor is SolarEdge Technologies Ltd. The affected software is the SolarEdge Monitoring Platform framework accessible at monitoring.solaredge.com.
