PT-2026-96050 · Scadabr · Scadabr

·

CVE-2026-94148

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions ScadaBR versions prior to 1.2.0
Description A remote information disclosure issue exists in the Export Project Endpoint component. The flaw is located in the EmportDwr.createExportJSON() function within the /ScadaBR/export project.htm file. This occurs because the export path was left unprotected, unlike the import path which is restricted by the Permissions.ensureAdmin() function.
Recommendations Update to version 1.2.0.

Exploit

Fix

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94148

Affected Products

Scadabr