CVE-2026-84860 is a high-severity vulnerability affecting ScadaLTS 2.8.1-release-candidate build 0, with an CVSS score of 8.8. The vulnerability is caused by an authorization bypass issue in Spring Security and DWR endpoints, allowing an authenticated user to invoke any DWR method by sending a request to a permitted URL while targeting a restricted class in the POST body.
CVE-2026-84859 is a vulnerability in ScadaLTS 2.8.1-release-candidate build 0, allowing authenticated users with ROLE_USER to perform blind SQL injection via /api/events/search. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. This issue arises from the endpoint's direct concatenation of user-input sortBy array values into the SQL ORDER BY clause without sanitization or parameterization [truncated]
CVE-2026-84858 debrief: ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass. The vulnerability exists in the DWR 'DataSourceEditDwr' class, which exposes the 'validateScript' method. This method compiles and executes attacker-supplied JavaScript via the Rhino scripting engine, allowing for Authenticated Remote Code Execution. Defender [truncated]
ScadaLTS 2.7.8.1 contains a reflected cross-site scripting vulnerability. The CVE record was published on 2026-08-12T20:17:43.060Z and has not been modified since then. Organizations should review and prioritize patching of affected ScadaLTS deployments, focusing on internet-exposed systems and those with high-priority operational roles. The vulnerability allows an unauthenticated attacker to execute arbi [truncated]
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process, leading to full compromise of the underlying system. The vulnerability's critical severity and potential impact necessitate immediate attent [truncated]