Authenticated Blind SQL Injection in ScadaLTS by ScadaLTS Inc.
CVE-2026-84859

6.5MEDIUM

Key Information:

Vendor

Scada-lts

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-84859?

ScadaLTS version 2.8.1-release-candidate build 0 contains an authenticated blind SQL injection vulnerability affecting the /api/events/search endpoint. The endpoint accepts a JSON body with a sortBy array, where the values are directly concatenated into the SQL ORDER BY clause without proper sanitization or parameterization. This oversight permits authenticated users, particularly those assigned the ROLE_USER role, to execute both time-based and boolean-based blind SQL injections, potentially allowing unauthorized access to sensitive database information, including user password hashes. The vulnerability remains accessible to all authenticated users across various roles, heightening the risk of data breaches.

Affected Version(s)

Scada-LTS 2.8.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.