Description
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass



The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via script sandbox bypass
Action: Immediate Patch
AI Analysis

Impact

Scada‑LTS version 2.8.1‑release‑candidate build 0 contains a flaw in the DWR "DataSourceEditDwr" class where the "validateScript" method compiles and executes attacker‑supplied JavaScript through Rhino. Because no authorization checks are performed, a user with any authenticated, even low‑privilege, account can trigger arbitrary code execution, potentially compromising the application's confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects only the Scada‑LTS product, specifically the 2.8.1‑release‑candidate build 0. No other Scada‑LTS versions are listed as vulnerable.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, classifying it as high severity, but the EPSS score of less than 1% indicates a low likelihood of active exploitation at this time. It is not listed in the CISA KEV catalog. An attacker would need to authenticate to the SCADA system, after which they could exploit the missing authorization and DWR routing bypass to execute arbitrary JavaScript, potentially spawning system commands with the process privileges of the SCADA service.

Generated by OpenCVE AI on September 18, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official patch that addresses the validateScript sandbox bypass.
  • Restrict access to the DWR "validateScript" endpoint by implementing network or application‑level ACLs for non‑administrative users.
  • Adjust user role definitions to prevent low‑privilege accounts from invoking scripting functionality, and regularly audit user accounts to remove unnecessary privileges.

Generated by OpenCVE AI on September 18, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Scada-lts
Scada-lts scada-lts
Vendors & Products Scada-lts
Scada-lts scada-lts

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.
Title Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Scada-lts Scada-lts
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-09-17T18:38:31.559Z

Reserved: 2026-09-02T13:26:19.179Z

Link: CVE-2026-84858

cve-icon Vulnrichment

Updated: 2026-09-17T18:38:27.511Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:18:00.527

Modified: 2026-09-18T19:18:42.907

Link: CVE-2026-84858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:45:02Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')