CVE-2026-9646: ScadaBR Unauthenticated Reflected Cross-Site Scripting
A reflected cross-site scripting issue exists in URL handling.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the ScadaBR web interface to trusted IPs/networks (for example via firewall rules, network ACLs, or VPN) to reduce exposure to unauthenticated reflected XSS in URL handling.
- Compensating control
Deploy a Web Application Firewall (WAF) or reverse proxy in front of ScadaBR with rules to detect and block common XSS payloads and malicious URL parameter values.
- Operational
Monitor web server and application logs for signs of attempted exploitation of URL-handling XSS; track vendor advisories and apply any official patches or updates for ScadaBR as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9646?
The severity of CVE-2026-9646 is categorized as medium with a score of 6.1.
What is CVE-2026-9646?
CVE-2026-9646 is an unauthenticated reflected cross-site scripting vulnerability that occurs in URL handling.
How do I fix CVE-2026-9646?
To fix CVE-2026-9646, ensure proper input validation and sanitization to prevent malicious scripts from being executed.
What types of attacks does CVE-2026-9646 allow?
CVE-2026-9646 allows attackers to execute arbitrary JavaScript code within the context of a victim's browser.
Which software is affected by CVE-2026-9646?
The vulnerability CVE-2026-9646 affects the ScadaBR software.