Executive brief
ScadaBR, an open-source software platform used for monitoring and controlling industrial processes (SCADA), contains a critical vulnerability that allows users with basic login credentials to execute malicious code. An attacker can use this flaw to take complete control of the server with administrative (root) privileges. This could lead to the total disruption of industrial operations, theft of sensitive operational data, or a complete system takeover.
Technical details
ScadaBR is vulnerable to remote code execution (RCE) due to exposed methods that allow authenticated users to create and execute arbitrary JavaScript code on the server. The vulnerability is classified as OS Command Injection (CWE-78) because the scripts execute with full system access, specifically running as the root user. An attacker with low-privileged network access can exploit this to achieve a complete system compromise. As of the advisory date, the project appears to be unmaintained, and no official patch or fix is available. Security researchers have indicated that the vulnerability has a high impact on confidentiality, integrity, and availability (CVSS 9.9).
Affected products
- ScadaBR ScadaBR All versions (unmaintained)
Timeline
- 2026-05-28: disclosed: Initial release of Tenable research advisory TRA-2026-46.
- 2026-05-28: advisory: CVE-2026-9645 published to the NVD.