CVE-2026-84858: Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass
The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs access to a low-privilege ScadaLTS user account. The vulnerable DWR method has no authorization checks, allowing that user to reach it through a DWR routing bypass.
What access does exploitation provide?
Successful exploitation allows authenticated remote code execution by supplying JavaScript that is compiled and executed by the Rhino scripting engine. The reported impact includes high confidentiality, integrity, and availability impact.
Which deployment is identified as affected?
The affected release identified in the report is ScadaLTS 2.8.1-release-candidate build 0.