Junglewise Threat Intelligence

CVE-2026-8603: ScadaBR OS command injection in SCADA system

CVE-2026-8603 · Severity: info · CVSS 8.8 · Published 2026-05-19

Vendors: ScadaBR.

Executive brief

ScadaBR is an open-source software platform used for monitoring and controlling industrial processes in sectors like energy, water, and manufacturing. A security flaw in version 1.2.0 allows an attacker to take full control of the system by executing commands with administrative (root) privileges. This could lead to the disruption of critical infrastructure, unauthorized changes to industrial processes, or the theft of sensitive operational data.

Technical details

An OS command injection vulnerability (CWE-78) exists in ScadaBR version 1.2.0. The flaw stems from improper neutralization of special elements used in an OS command, allowing an attacker with low-privileged network access to inject and execute arbitrary commands with root-level permissions. This can lead to full system compromise, including complete loss of confidentiality, integrity, and availability. As of the advisory date, the vendor has not responded to mitigation requests, and no official patch is available. Organizations are advised to isolate SCADA networks from the internet and use VPNs for remote access.

Affected products

  • ScadaBR ScadaBR 1.2.0

Timeline

  • 2026-05-19: advisory: CISA and NVD published the advisory.
  • 2026-05-19: disclosed: Initial public disclosure of the vulnerability.

References