CVE-2026-8604: Cross-Site request forgery (CSRF) in ScadaBR
Published May 19, 2026
·Updated
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
Affected Software
2 affected components
ScadaBR ScadaBR=1.2.0
ScadaBR ScadaBR=1.2
Event History
May 19, 2026
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 29, 58424
Event
via FIRST·07:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8604?
CVE-2026-8604 has a moderate severity level due to the potential for unauthorized actions through CSRF.
2
How do I fix CVE-2026-8604?
To fix CVE-2026-8604, update ScadaBR to version 1.2.1 or later, where the vulnerability is addressed.
3
What systems are affected by CVE-2026-8604?
CVE-2026-8604 affects ScadaBR version 1.2.0.
4
What type of vulnerability is CVE-2026-8604?
CVE-2026-8604 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What does CVE-2026-8604 allow an attacker to do?
CVE-2026-8604 allows an attacker to perform authenticated actions on behalf of users without their consent.