PatchSiren cyber security CVE debrief
CVE-2026-8602 ScadaBR CVE debrief
CVE-2026-8602 describes a missing authentication issue in ScadaBR 1.2.0 that can let an unauthenticated attacker send HTTP GET requests to the SCADA system and inject arbitrary sensor readings. Because the issue is reachable over the network and affects integrity and availability, exposed deployments should treat it as high priority.
- Vendor
- ScadaBR
- Product
- Unknown
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-19
Who should care
Operators and defenders responsible for ScadaBR 1.2.0, especially OT/ICS environments with SCADA access exposed beyond a tightly controlled network. Security teams monitoring industrial systems should also review related logs and network controls.
Technical summary
The supplied NVD record describes CVE-2026-8602 as a Missing Authentication for Critical Function issue in ScadaBR version 1.2.0. The weakness is mapped to CWE-306. An unauthenticated attacker may be able to send HTTP GET requests to the SCADA system and inject arbitrary sensor readings. The NVD metadata lists the issue as awaiting analysis and includes a network-based CVSS v4.0 vector with no privileges required and high integrity/availability impact.
Defensive priority
Immediate for any exposed or production ScadaBR 1.2.0 deployment.
Recommended defensive actions
- Confirm whether ScadaBR 1.2.0 is in use anywhere in the environment, including lab, test, and production segments.
- Restrict network access to the SCADA interface to trusted management networks and required service accounts only.
- Verify whether authentication is enforced on all critical functions and disable or isolate any unauthenticated access paths.
- Review application, reverse proxy, and network logs for unexpected HTTP GET activity and unexplained sensor value changes.
- Apply vendor or CISA guidance from the linked advisory and prioritize remediation before broader internet or IT network exposure.
- Validate sensor data against independent telemetry or control logic to detect tampering until a fix is in place.
Evidence notes
This debrief is based on the supplied NVD record for CVE-2026-8602, published 2026-05-19 and modified 2026-05-19, plus the linked CISA ICS advisory reference. The NVD metadata states vulnStatus 'Awaiting Analysis,' identifies CWE-306, and describes unauthenticated HTTP GET requests enabling arbitrary sensor reading injection in ScadaBR 1.2.0. No KEV entry was provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8602 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8602
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8602 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8602
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-03
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.