Executive brief
ScadaBR is an open-source software platform used to manage and monitor industrial control systems (ICS) in sectors like energy, water, and manufacturing. A security flaw in version 1.2.0 involves the use of fixed, unchangeable login credentials within the software. If discovered, an attacker could use these credentials to gain administrative access to the system, potentially allowing them to interfere with critical infrastructure operations or view sensitive industrial data.
Technical details
A Use of Hard-coded Credentials vulnerability (CWE-798) exists in ScadaBR version 1.2.0. The software contains fixed authentication secrets that are not unique to the installation, which can be leveraged by an attacker to authenticate as an administrator. While the CVSS vector indicates a requirement for user interaction (UI:R), the primary root cause is the presence of static credentials within the application code or configuration. Successful exploitation grants full administrative privileges over the SCADA environment. As of the advisory date, the vendor has not responded to mitigation requests, and no official patch is available; users are advised to isolate the system from the internet and use VPNs for remote access.
Affected products
- ScadaBR ScadaBR 1.2.0
Timeline
- 2026-05-19: advisory: Initial publication of ICSA-26-139-03
- 2026-05-19: disclosed