Scadabr: community verdicts
6 notable / known-exploited Scadabr CVEs the community has triaged.
- CVE-2021-26829MED 5.4KEVEPSS 48%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
- CVE-2021-26828HIGH 8.8KEVEPSS 39%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
- CVE-2026-8603CRIT 9.8Real · low riskEPSS 1%
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
- CVE-2026-8602CRIT 9.1Real · low riskEPSS 0%
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
- CVE-2026-8605CRIT 9.8Real · low riskEPSS 0%
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
- CVE-2026-8604HIGH 8.8Real · low riskEPSS 0%
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.