CVE-2026-8602: Missing authentication for critical function in ScadaBR
Published May 19, 2026
·Updated
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
Affected Software
2 affected components
ScadaBR ScadaBR=1.2.0
ScadaBR ScadaBR=1.2
Event History
May 19, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 29, 58424
Event
via FIRST·04:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8602?
CVE-2026-8602 has a high severity rating of 8.8 according to the CVSS system.
2
How do I fix CVE-2026-8602?
To fix CVE-2026-8602, ensure that proper authentication mechanisms are implemented for critical functions in ScadaBR.
3
What are the potential impacts of CVE-2026-8602?
The potential impacts of CVE-2026-8602 include unauthorized access to the SCADA system and the ability for attackers to inject arbitrary sensor readings.
4
Which version of ScadaBR is affected by CVE-2026-8602?
CVE-2026-8602 affects ScadaBR version 1.2.0.
5
Can an attacker exploit CVE-2026-8602 remotely?
Yes, an unauthenticated attacker can exploit CVE-2026-8602 remotely by sending HTTP GET requests to the SCADA system.