Junglewise Threat Intelligence

CVE-2021-26828: OpenPLC ScadaBR unrestricted file upload in view_edit.shtm

CVE-2021-26828 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-12-03

Technologies: OpenPLC SCADABr. Vendors: OpenPLC.

Executive brief

OpenPLC ScadaBR is an open-source platform used for automation and monitoring in industrial environments. A security flaw allows an authorized user to upload malicious files to the system, which can then be executed to take full control of the server. This could lead to the disruption of industrial processes, theft of sensitive operational data, or a complete system shutdown.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in OpenPLC ScadaBR through version 0.9.1 on Linux and 1.12.4 on Windows. The flaw is located in the 'view_edit.shtm' component, which fails to properly validate file extensions or content types during the upload process. A remote attacker with low-level authentication can upload a malicious JavaServer Pages (JSP) file and access it via the web server to achieve arbitrary code execution. This vulnerability has been observed being exploited in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • OpenPLC Project ScadaBR Linux up to 0.9.1, Windows up to 1.12.4

Timeline

  • 2021-06-11: disclosed: Initial NVD publication
  • 2025-12-03: kev added: Added to CISA KEV catalog due to active exploitation

Related threats