Unauthorized Command Execution in ScadaLTS by Scada Technology
CVE-2026-19656
9.9CRITICAL
What is CVE-2026-19656?
The ScadaLTS version 2.7.8.1 exposes a server-side method that does not implement necessary authorization checks. This allows authenticated users, even those with basic read-only access, to execute arbitrary operating system commands on the host server. If successfully exploited, this vulnerability can result in code execution within the context of the ScadaLTS server process, potentially leading to a complete compromise of the underlying system.
Affected Version(s)
ScadaLTS 2.7.8.1
