CVE-2026-9645

Source
https://cve.org/CVERecord?id=CVE-2026-9645
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9645.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-9645
Published
2026-05-28T20:30:13Z
Modified
2026-08-19T03:49:05Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
ScadaBR Authenticated Remote Code Execution
Details

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

Database specific
{
    "cna_assigner": "tenable",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9645.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.2.0"
                },
                {
                    "last_affected": "1.2.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/scadabr/scadabr

Affected ranges

Type
GIT
Repo
https://github.com/scadabr/scadabr
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:scadabr:scadabr:1.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.2"
        },
        {
            "last_affected": "1.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.2
v1.*
v1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9645.json"