Description
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.
Published: 2026-08-12
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from a server‑side method that omits authorization checks. Any authenticated user, even one with read‑only permissions, can invoke this endpoint to execute arbitrary operating‑system commands. The commands run with root privileges because the ScadaLTS server process itself operates as root, allowing an attacker to fully compromise the underlying host. This flaw is a classic example of missing authorization (CWE‑862).

Affected Systems

The reported exposed method exists in the ScadaLTS product from SCADA‑LTS, specifically version 2.7.8.1. No other versions are listed as affected in the advisory.

Risk and Exploitability

The CVSS score of 9.9 signals a severe impact and low exploitation complexity. The EPSS score is not available, and the vulnerability is not yet included in CISA’s KEV catalog. Exploitation requires that an attacker obtain valid credentials—whether through phishing, credential theft, or by using an existing low‑privilege account. Once authenticated, the attacker can execute arbitrary code with full root rights on the device, leading to systemic compromise.

Generated by OpenCVE AI on August 12, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest ScadaLTS release that removes the vulnerable method (version 2.7.8.1 is confirmed insecure).
  • Revoke or upgrade the privileges of non‑administrative accounts so that only administrators can authenticate to the ScadaLTS API.
  • Apply firewall or network segmentation rules to block external access to the vulnerable endpoint, or isolate the server behind an access‑control gateway until a patch is applied.

Generated by OpenCVE AI on August 12, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:scada-lts:scada-lts:2.7.8.1:*:*:*:*:*:*:*

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Scada-lts
Scada-lts scada-lts
Vendors & Products Scada-lts
Scada-lts scada-lts

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.
Title ScadaLTS Authenticated Remote Code Execution
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Scada-lts Scada-lts
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-08-12T19:29:48.517Z

Reserved: 2026-08-12T18:52:22.952Z

Link: CVE-2026-19656

cve-icon Vulnrichment

Updated: 2026-08-12T19:29:43.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:42.933

Modified: 2026-08-25T14:08:10.327

Link: CVE-2026-19656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses