CVE-2026-19657: ScadaLTS Unauthenticated Reflected XSS
Published Aug 12, 2026
·Updated
ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
Affected Software
1 affected component
ScadaLTS ScadaLTS=2.7.8.1
Event History
Aug 12, 2026
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19657?
CVE-2026-19657 has a medium severity rating of 6.1.
2
How do I fix CVE-2026-19657?
To mitigate CVE-2026-19657, update ScadaLTS to the latest version where the vulnerability is addressed.
3
What type of vulnerability is CVE-2026-19657?
CVE-2026-19657 is classified as an unauthenticated reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-19657?
CVE-2026-19657 affects users of ScadaLTS version 2.7.8.1 and earlier versions.
5
What can an attacker do with CVE-2026-19657?
An attacker can execute arbitrary JavaScript in the victim's browser session by enticing them to visit a specially crafted URL.