CVE-2026-84859: Scada-LTS Authenticated Blind SQL Injection

Published Sep 16, 2026
·
Updated

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection

The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQL ORDER BY clause without any sanitization or parameterization. This allows authenticated users with the ROLEUSER role to perform time-based and boolean-based blind SQL injection to extract arbitrary data from the database, including password hashes of all users.

The endpoint is accessible to any authenticated user with ROLEUSER, ROLEADMIN, or ROLEPUBLIC via POST /api/events/search as defined in spring-security.xml.

Affected Software

1 affected component
ScadaLTS=2.8.1-release-candidate build 0

Event History

Sep 16, 2026
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverity

Frequently Asked Questions

1

Which accounts can reach the affected endpoint?

Any authenticated account with ROLE_USER, ROLE_ADMIN, or ROLE_PUBLIC can access POST /api/events/search. Exploitation requires authentication, and ROLE_USER is sufficient.

2

What could an attacker obtain through this issue?

An attacker can use time-based or boolean-based blind SQL injection to extract arbitrary database data, including password hashes for all users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203