CVE-2026-19656
Analyzed Analyzed - Analysis Complete

Remote Code Execution in ScadaLTS

Vulnerability report for CVE-2026-19656, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-25

Assigner: Tenable Network Security, Inc.

Description

ScadaLTS 2.7.8.1Β exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-25
Generated
2026-09-02
AI Q&A
2026-08-13
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
scada-lts scada-lts 2.7.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ScadaLTS 2.7.8.1 has a server-side method that does not require proper authorization checks. This flaw allows any authenticated user, even those with low-privilege or read-only access, to run arbitrary operating system commands on the server. The commands execute with root privileges, giving attackers full control over the system.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized command execution capabilities in ScadaLTS 2.7.8.1. Inspect server logs for unusual system command patterns or unexpected process executions. Verify if low-privilege users can trigger OS commands via the exposed server-side method.

Impact Analysis

This vulnerability allows attackers to take complete control of the ScadaLTS server. They can install malware, steal data, disrupt operations, or pivot to other systems in the network. Even low-privilege users pose a significant risk due to the lack of authorization checks.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA due to unauthorized system access and potential data breaches. It undermines data integrity, confidentiality, and availability, which are core principles in these regulations.

Mitigation Strategies

Immediately upgrade ScadaLTS to a patched version if available. If no patch exists, restrict user permissions to the minimum required and disable low-privilege users' ability to execute OS commands. Monitor network traffic for suspicious activity targeting ScadaLTS services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19656. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart