CVE-2026-84858: Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass

Published Sep 16, 2026
·
Updated

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass

The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.

Affected Software

1 affected component
ScadaLTS=2.8.1-release-candidate build 0

Event History

Sep 16, 2026
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverity

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs access to a low-privilege ScadaLTS user account. The vulnerable DWR method has no authorization checks, allowing that user to reach it through a DWR routing bypass.

2

What access does exploitation provide?

Successful exploitation allows authenticated remote code execution by supplying JavaScript that is compiled and executed by the Rhino scripting engine. The reported impact includes high confidentiality, integrity, and availability impact.

3

Which deployment is identified as affected?

The affected release identified in the report is ScadaLTS 2.8.1-release-candidate build 0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203