CVE-2026-9645 PUBLISHED

ScadaBR Authenticated Remote Code Execution

Assigner: tenable
Reserved: 26.05.2026 Published: 28.05.2026 Updated: 28.05.2026

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor ScadaBR
Product ScadaBR
Versions Default: unaffected
  • Version 1.2.0 is affected

Credits

  • Derrie Sutton with Tenable finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-549 Local Execution of Code