LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-19656

scada-lts · scada-lts

Published
CVSS9.9
Severitycritical
WeaknessCWE-862
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-19656

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-19656.