CVE-2026-19656

9.9

SCADA-LTS · ScadaLTS

ScadaLTS 2.7.8.1 contains an authorization bypass vulnerability that allows authenticated users with low privileges to execute arbitrary operating system commands as root.

Executive summary

An authorization vulnerability in ScadaLTS allows low-privileged users to escalate their access and execute arbitrary commands with root privileges on the server.

Vulnerability

The application lacks necessary authorization checks for certain server-side methods. This permits any user with read-only access to invoke administrative functions, leading to OS command injection in the context of the root user.

Business impact

With a CVSS score of 9.9, this vulnerability represents a severe threat to operational technology environments. Successful exploitation allows an attacker to gain full control over the ScadaLTS server, potentially disrupting industrial processes or accessing sensitive control network data.

Remediation

Immediate Action: Since a specific patch version is not currently identified in the provided data, users should contact the vendor for the latest security release or apply vendor-provided mitigations.

Proactive Monitoring: Monitor system logs for unauthorized attempts to access server-side administrative methods or unexpected process execution by the ScadaLTS application user.

Compensating Controls: Implement strict network segmentation to isolate the ScadaLTS instance and enforce the principle of least privilege for all user accounts accessing the platform.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing ScadaLTS must treat this as a high-priority security incident. Given the potential for full system compromise, restrict access to the application immediately and engage with the vendor to obtain the necessary security updates or configuration changes to address the authorization flaw.