PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84858 Scada-LTS CVE debrief

CVE-2026-84858 debrief: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass. The vulnerability exists in the DWR 'DataSourceEditDwr' class, which exposes the 'validateScript' method. This method compiles and executes attacker-supplied JavaScript via the Rhino scripting engine, allowing for Authenticated Remote Code Execution. Defenders should assess exposure and potential impact, prioritizing verification of ScadaLTS version and exposure.

Vendor
Scada-LTS
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Defenders responsible for ScadaLTS deployments should assess exposure and potential impact, prioritizing verification of ScadaLTS version and exposure. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

CVE-2026-84858 is a high-severity vulnerability in ScadaLTS 2.8.1-release-candidate build 0 that allows for Authenticated Remote Code Execution via Scripting Sandbox Bypass. Defenders should prioritize verifying exposure and assessing potential impact.

  • Potential remote code execution requires verification of ScadaLTS version and exposure
  • Authenticated exploitation may lead to system compromise

Technical summary

The DWR 'DataSourceEditDwr' class exposes the 'validateScript' method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine, allowing for Authenticated Remote Code Execution. This vulnerability affects ScadaLTS 2.8.1-release-candidate build 0. Defenders should prioritize verifying exposure and assessing potential impact, focusing on the affected product context and defensive impact without unsupported root-cause or exploit claims. The vulnerability allows an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact.

Recommended defensive actions

  • Verify ScadaLTS version and assess exposure
  • Implement compensating controls to limit potential impact
  • Monitor for potential exploitation attempts
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence from the CVE Program and NVD suggests that ScadaLTS 2.8.1-release-candidate build 0 is vulnerable to Authenticated Remote Code Execution. The DWR 'DataSourceEditDwr' class exposes the 'validateScript' method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method, allowing an attacker with access to a low privilege user to abuse this flaw.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84858 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84858

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84858 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84858

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.