CVE-2026-19656 PUBLISHED

ScadaLTS Authenticated Remote Code Execution

Assigner: tenable
Reserved: 12.08.2026 Published: 12.08.2026 Updated: 12.08.2026

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor SCADA-LTS
Product ScadaLTS
Versions Default: unaffected
  • Version 2.7.8.1 is affected

Credits

  • Derrie Sutton, Tenable Research finder

References

Problem Types

  • CWE-862 CWE

Impacts

  • CAPEC-122 Privilege Abuse