CVE-2026-19657
Analyzed Analyzed - Analysis Complete

Stored XSS Vulnerability in ScadaLTS

Vulnerability report for CVE-2026-19657, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-25

Assigner: Tenable Network Security, Inc.

Description

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-25
Generated
2026-09-02
AI Q&A
2026-08-13
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
scada-lts scada-lts 2.7.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated reflected cross-site scripting (XSS) vulnerability in ScadaLTS version 2.7.8.1. User input is reflected in HTML responses without sanitization, allowing an attacker to execute arbitrary JavaScript in a victim's browser by tricking them into visiting a crafted URL.

Detection Guidance

To detect this vulnerability, monitor network traffic for suspicious URLs or HTTP responses containing unfiltered user input. Check ScadaLTS version 2.7.8.1 for reflected input in HTML responses. Test by sending crafted URLs to the system and observing if JavaScript executes.

Impact Analysis

An attacker could steal session cookies, perform actions on behalf of the victim, or redirect them to malicious sites. This could lead to unauthorized access to sensitive data or control of the user's browser session.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. It may result in unauthorized access to personal or sensitive data.

Mitigation Strategies

Upgrade to ScadaLTS version 2.8.1 or later once available, as the vendor confirmed the issue is resolved in this release. Until then, restrict access to the system, avoid clicking untrusted links, and implement input sanitization if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19657. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart