PT-2026-93806 · Scada-Lts · Scada-Lts

CVE-2026-84860

·

Published

2026-09-16

·

Updated

2026-09-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ScadaLTS version 2.8.1-release-candidate build 0
Description An authorization bypass exists because Spring Security restricts DWR endpoints using URL path patterns, while DWR dispatches method calls based on the c0-scriptName and c0-methodName parameters in the POST body. Since the crossDomainSessionSecurity setting in web.xml is disabled, any authenticated user can invoke restricted DWR methods by sending a request to a permitted URL while specifying a restricted class in the POST body. This issue serves as a root cause that allows low-privilege users to exploit other vulnerabilities.
Recommendations Update ScadaLTS version 2.8.1-release-candidate build 0 to a patched version.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84860

Affected Products

Scada-Lts