CVE-2026-84858 Details
Description
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.
A remote code execution vulnerability has been identified in ScadaLTS version 2.8.1-release-candidate build 0. This issue arises from an authenticated remote code execution via a scripting sandbox bypass. The vulnerability is located in the DWR 'DataSourceEditDwr' class, which exposes the 'validateScript' method. This method compiles and executes JavaScript supplied by the attacker using the Rhino scripting engine. The lack of authorization checks on this method allows low-privilege users to exploit this flaw by bypassing DWR's routing restrictions.
At the time of publication, no patched version is available. Users should contact Scada-LTS for guidance on obtaining a fixed version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tenable.com/security/research/tra-2026-60 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ScadaLTS | 2.8.1-release-candidate build 0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion