Remote Code Execution in ScadaLTS Web Application by Unauthenticated Attackers
CVE-2026-19657

6.1MEDIUM

Key Information:

Vendor

Scada-lts

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-19657?

ScadaLTS 2.7.8.1 is susceptible to a cross-site scripting vulnerability due to improper handling of user-supplied input. This flaw enables an unauthenticated attacker to manipulate input, resulting in arbitrary JavaScript execution within the user's browser session when the victim is enticed to follow a specially crafted URL. As the input is reflected back in the HTML response without adequate sanitization, this issue poses significant risks, including data theft and session hijacking.

Affected Version(s)

ScadaLTS 2.7.8.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Derrie Sutton, Tenable Research
.