AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19656

CRITICAL · CVSS 9.9 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

ScadaLTS 2.7.8.1 contains a critical vulnerability that allows any authenticated user, even those with minimal permissions, to execute arbitrary operating system commands on the host due to insufficient authorization checks. This exploitation can lead to complete system compromise, as the commands run with root privileges in the context of the ScadaLTS server process. Organizations using this version of ScadaLTS should prioritize immediate remediation to mitigate the risk of unauthorized access and potential system takeover.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19656
Severity
CRITICAL
CVSS
9.9
EPSS
0.29%

Original NVD Description

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.