CVE-2026-9645: ScadaBR Authenticated Remote Code Execution
Published May 28, 2026
·Updated
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
Affected Software
1 affected component
ScadaBR ScadaBR
Event History
May 28, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·10:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-9645?
CVE-2026-9645 has a critical severity score of 9.9.
2
How do I fix CVE-2026-9645?
To fix CVE-2026-9645, ensure that all users have appropriate access controls and update ScadaBR to the latest secure version.
3
What impact does CVE-2026-9645 have on my system?
CVE-2026-9645 allows authenticated users to execute arbitrary JavaScript code, potentially leading to complete system compromise.
4
Who is affected by CVE-2026-9645?
CVE-2026-9645 affects ScadaBR installations where authenticated users can access the vulnerable methods.
5
What type of vulnerability is CVE-2026-9645 classified as?
CVE-2026-9645 is classified as an OS Command Injection vulnerability.