CVE-2026-19656

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.
References
Link Resource
https://www.tenable.com/security/research/tra-2026-55 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:scada-lts:scada-lts:2.7.8.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 20:17

Updated : 2026-08-25 14:08


NVD link : CVE-2026-19656

Mitre link : CVE-2026-19656

CVE.ORG link : CVE-2026-19656


JSON object : View

Products Affected

scada-lts

  • scada-lts
CWE
CWE-862

Missing Authorization