CVE-2026-19656

Source
https://cve.org/CVERecord?id=CVE-2026-19656
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19656.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19656
Published
2026-08-12T19:10:11Z
Modified
2026-08-27T11:47:28Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
ScadaLTS Authenticated Remote Code Execution
Details

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.

Database specific
{
    "cna_assigner": "tenable",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19656.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.7.8.1"
                },
                {
                    "last_affected": "2.7.8.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/scada-lts/scada-lts

Affected ranges

Type
GIT
Repo
https://github.com/scada-lts/scada-lts
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:scada-lts:scada-lts:2.7.8.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.7.8.1"
        },
        {
            "last_affected": "2.7.8.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.7.8.1
v2.*
v2.7.8.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19656.json"