CVE-2026-84858
nicheAuthenticated RCE via Rhino Script Sandbox Bypass in ScadaLTS 2.8.1
ScadaLTS 2.8.1-release-candidate build 0 contains an authenticated remote code execution flaw caused by a scripting sandbox bypass. The DWR (Direct Web Remoting) class DataSourceEditDwr exposes a validateScript method that compiles and executes attacker-supplied JavaScript through the Rhino scripting engine, and this method has no authorization checks. A low-privilege authenticated user can invoke validateScript via a DWR routing bypass, causing their JavaScript to run on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the SCADA host (CVSS 8.8), effectively giving the attacker code execution as the web application service account. No exploitation has been reported and no public proof-of-concept is known; the issue was assigned by Tenable's CNA.
What to do: Upgrade ScadaLTS to a fixed release as soon as the vendor publishes one (no fixed version is identified in the available data), and in the meantime restrict which accounts can reach the DWR endpoints and limit network access to the web interface to trusted operators only. Review data sources and scripting configurations for unauthorized edits, monitor validateScript/DataSourceEditDwr requests in web logs, and ensure low-privilege users cannot reach the SCADA server's HTTP service from untrusted networks.
| ScadaLTS (open-source SCADA platform) | 2.8.1-release-candidate build 0 (additional affected ranges not specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.