PT-2026-93806 · Scada-Lts · Scada-Lts
CVE-2026-84860
·
Published
2026-09-16
·
Updated
2026-09-30
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ScadaLTS version 2.8.1-release-candidate build 0
Description
An authorization bypass exists because Spring Security restricts DWR endpoints using URL path patterns, while DWR dispatches method calls based on the
c0-scriptName and c0-methodName parameters in the POST body. Since the crossDomainSessionSecurity setting in web.xml is disabled, any authenticated user can invoke restricted DWR methods by sending a request to a permitted URL while specifying a restricted class in the POST body. This issue serves as a root cause that allows low-privilege users to exploit other vulnerabilities.Recommendations
Update ScadaLTS version 2.8.1-release-candidate build 0 to a patched version.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scada-Lts