Scadabr · Scadabr · CVE-2026-94148
**Name of the Vulnerable Software and Affected Versions**
ScadaBR versions prior to 1.2.0
**Description**
A remote information disclosure issue exists in the Export Project Endpoint component. The flaw is located in the `EmportDwr.createExportJSON()` function within the `/ScadaBR/export project.htm` file. This occurs because the export path was left unprotected, unlike the import path which is restricted by the `Permissions.ensureAdmin()` function.
**Recommendations**
Update to version 1.2.0.