Junglewise Threat Intelligence

CVE-2026-10058: ITP Technology ITS Intelligent SCADA System Stored XSS

CVE-2026-10058 · Severity: medium · CVSS 4.8 · Published 2026-05-29

Executive brief

The ITS Intelligent SCADA System, used for monitoring and controlling industrial processes, contains a security flaw that allows an authorized user with high-level privileges to plant malicious scripts within the system. When other users or administrators view the affected pages, these scripts execute automatically in their web browsers. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the ITS Intelligent SCADA System version 2.1 due to improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker with high privileges (PR:H) can inject malicious JavaScript into specific pages of the application. This code is persistently stored on the server and executes in the context of any user's browser session when they navigate to the compromised page. While the attack requires administrative-level access to initiate, it can be used to target other high-privileged users, potentially leading to session hijacking or unauthorized configuration changes within the SCADA environment.

Affected products

  • ITP Technology ITS Intelligent SCADA System 2.1

Timeline

  • 2026-05-29: disclosed: Initial disclosure by TWCERT/CC
  • 2026-05-29: advisory: NVD publication date

References

Related threats