Junglewise Threat Intelligence

CVE-2026-8603: ScadaBR missing authentication for sensor data injection

CVE-2026-8603 · Severity: high · CVSS 9.1 · Published 2026-05-19

Executive brief

ScadaBR is an open-source software platform used for monitoring and controlling industrial processes in sectors like energy, water, and manufacturing. A security flaw allows unauthorized individuals to send commands to the system without logging in, enabling them to submit fake sensor data. This could lead to incorrect operational decisions, equipment damage, or safety risks by tricking operators into believing a process is in a state it is not.

Technical details

A Missing Authentication for Critical Function vulnerability (CWE-306) exists in ScadaBR version 1.2.0. The flaw allows an unauthenticated attacker with network access to the SCADA system to send crafted HTTP GET requests that bypass security checks. By exploiting this, an attacker can inject arbitrary sensor readings, potentially compromising the integrity of the industrial process monitoring and causing operational disruptions. As of the advisory date, the vendor has not responded to mitigation requests, and users are advised to isolate control systems from the internet and use VPNs for remote access.

Affected products

  • ScadaBR ScadaBR 1.2.0

CVE identifiers

  • CVE-2026-8603
  • CVE-2026-8604
  • CVE-2026-8605
  • CVE-2026-8602

Timeline

  • 2026-05-19: advisory: CISA and NVD published the advisory (ICSA-26-139-03)

References