Cross-Site Scripting Vulnerability in URL Handling for Tenable Products
CVE-2026-9646

6.1MEDIUM

Key Information:

Vendor

Scadabr

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-9646?

A reflected cross-site scripting vulnerability allows attackers to inject malicious scripts through manipulated URLs. This vulnerability can lead to unauthorized actions by users who click on crafted links, potentially compromising their sensitive information. Users are advised to remain vigilant and implement proper input validation and output encoding to mitigate this issue.

Affected Version(s)

ScadaBR 1.2.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Derrie Sutton with Tenable
.