Search

Predbat v8.54.3 released with a critical security fix for credential leakage

Predbat has published a security update that stops its home battery control software leaking credentials through apps.yaml downloads and debug dumps, alongside a set of smaller fixes.

A newspaper on a kitchen table beside a model of smart meters

Predbat, the open-source home battery and solar control tool, published a release on 2 September 2026 described in its own notes as "Bug fixes, AI chat improvements and critical security fix (key filtering)"1. The security element addresses credential leakage from apps.yaml downloads and debug dumps, according to the release notes1.

The same release carries a set of smaller changes. These include making the number of retained log files configurable, adding a manual_soc_max setting described as "a discharge-direction ceiling sibling to manual_soc", and a fix so that Solis retries stop draining the SolisCloud daily API allowance1. A further fix selects Self-Consumption Grid for a Sigenergy Cloud freeze export, and Fox CLI credentials can now be loaded from an apps.yaml file with --config1.

The release sits inside a run of frequent updates. Earlier entries in the same series include "FoxCloud FeedIn First, GECloud 3-phase fix, Misc bugs & docs" and "Tesla alternative optimiser, bug fixes"1.

"Bug fixes, AI chat improvements and critical security fix (key filtering)"
Predbat release notes, 2 September 20261
ItemChange in the 2 September 2026 release
SecurityKey filtering to stop credential leakage from apps.yaml downloads and debug dumps1
LoggingNumber of retained log files made configurable1
Battery controlmanual_soc_max added as a discharge-direction ceiling1
SolisRetries no longer drain the SolisCloud daily API allowance1
SigenergySelf-Consumption Grid selected for a Cloud freeze export1

Why it matters for households

Predbat is software that sits between a home's inverter, battery and tariff data and decides when to charge or discharge. To do that it holds credentials for cloud services such as inverter portals and tariff accounts. A leak of those credentials through a downloaded configuration file or a debug dump is a direct risk to a household's energy account, not just to the software. The key filtering in this release is the part that closes that route1.

The other changes are operational. A configurable log retention limit matters on the small always-on computers many homes run this kind of control software on, where logs can accumulate. The Solis fix protects a daily API allowance, which if exhausted would leave the software unable to read the inverter. The manual_soc_max setting gives a ceiling in the discharge direction, the counterpart to the existing manual_soc floor1.

For a home's energy independence, the practical point is that the control layer is what turns a battery and solar array into something that can be run against a tariff rather than simply charged and discharged. Software faults in that layer show up as missed cheap-rate windows or unwanted export, not as hardware failure. Details of how home energy management systems and metering fit together are set out in the smart-meters-hems hub.

What happens next

No end-of-support date for the earlier line, and no statement on whether the credential leakage affected any installations before the fix, has been reported1.

Sources1 cited
  1. [](https://github.com/springfall2008/batpred/releases.atom), github.com