Description
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass



Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body.



This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Update System
AI Analysis

Impact

The vulnerability allows any authenticated user to invoke any DWR method by placing the target class name and method into the POST body, thereby bypassing the URL‑based Spring Security controls. The flaw is a classic authority and access control weakness (CWE-639) where the application trusts request parameters over established access policies. An attacker with legitimate credentials can therefore execute restricted server‑side logic, potentially exposing, modifying, or deleting protected data or performing other privileged operations.

Affected Systems

Scada‑LTS version 2.8.1‑release‑candidate build 0 is affected. No other vendor or product versions were identified as vulnerable.

Risk and Exploitability

The CVSS score of 8.8 marks it as high severity and the EPSS score of < 1 % indicates a low likelihood of widespread exploitation at this time. It is not listed in the CISA KEV catalog. The attack requires a valid authenticated session and access to a DWR URL that the attacker can target. Because the application does not validate request origins when crossDomainSessionSecurity is disabled, a malicious actor can send a crafted POST body to any accessible DWR endpoint and direct the call to a restricted class, enabling the exploitation of multiple downstream weaknesses.

Generated by OpenCVE AI on September 18, 2026 at 03:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade Scada‑LTS to a non‑vulnerable release to eliminate the code path that permits unrestricted DWR method invocation.
  • Enable crossDomainSessionSecurity in web.xml or otherwise enforce origin validation so that DWR only processes requests with a valid origin header. This mitigates the authority failure (CWE‑639).
  • Enforce strict role‑based access control for all classes exposed via DWR and monitor for suspicious invocation patterns. Ensure that only authorized roles can call protected methods.
  • Regularly check the vendor’s website or support portal for updates and security advisories until a patched version is available.

Generated by OpenCVE AI on September 18, 2026 at 03:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Scada-lts
Scada-lts scada-lts
Vendors & Products Scada-lts
Scada-lts scada-lts

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body. This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.
Title Scada-LTS DWR Authorization Bypass - Systemic
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Scada-lts Scada-lts
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-09-17T18:37:14.382Z

Reserved: 2026-09-02T13:26:23.692Z

Link: CVE-2026-84860

cve-icon Vulnrichment

Updated: 2026-09-17T18:37:03.855Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:18:00.760

Modified: 2026-09-18T19:18:42.907

Link: CVE-2026-84860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:45:02Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key