Junglewise Threat Intelligence

CVE-2026-9646: ScadaBR reflected cross-site scripting in URL handling

CVE-2026-9646 · Severity: medium · CVSS 6.1 · Published 2026-05-28

Vendors: ScadaBR.

Executive brief

ScadaBR, an open-source software used for monitoring and controlling industrial processes (SCADA), is vulnerable to a security flaw in how it handles web addresses. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions or sensitive information displayed within the application.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in ScadaBR due to improper neutralization of script-related HTML tags within URL handling (CWE-80). The vulnerability is reachable over the network without authentication, though it requires user interaction (e.g., clicking a crafted link). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. As of the advisory date, the project appears to be unmaintained and no official patch is available.

Affected products

  • ScadaBR ScadaBR

Timeline

  • 2026-05-28: advisory: Initial release of Tenable Research Advisory TRA-2026-46
  • 2026-05-28: disclosed: NVD publication date

References