CVE-2026-19657 PUBLISHED

ScadaLTS Unauthenticated Reflected XSS

Assigner: tenable
Reserved: 12.08.2026 Published: 12.08.2026 Updated: 12.08.2026

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor SCADA-LTS
Product ScadaLTS
Versions Default: unaffected
  • Version 2.7.8.1 is affected

Credits

  • Derrie Sutton, Tenable Research finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS