AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19657

MEDIUM · CVSS 6.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects ScadaLTS 2.7.8.1, where user-supplied input is reflected in HTML responses without proper sanitization. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser by tricking them into visiting a malicious URL, potentially leading to session hijacking or data theft. Organizations using this version of ScadaLTS should prioritize remediation to mitigate the risk of client-side attacks.

CVE
CVE-2026-19657
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%
Java

Original NVD Description

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.