CVE-2026-19656
Last modified
CVE-2026-19656 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Scada-Lts | Scada-Lts | 2.7.8.1 |
References
- https://www.tenable.com/security/research/tra-2026-55Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19656?
How severe is CVE-2026-19656?
How do I fix CVE-2026-19656?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1965libcurl can in some circumstances reuse the wrong connection…6.5
- CVE-2026-19650GitLab has remediated an issue in GitLab CE/EE affecting all…7.1
- CVE-2026-19651IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3…7.4
- CVE-2026-19653IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …5.5
- CVE-2026-19654A unauthenticated remote peer may lead rsyslogd to crash due…7.5
- CVE-2026-19655On affected platforms running Arista EOS with Dynamic Host C…6.5
- CVE-2026-19657ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML r…6.1
- CVE-2026-1966YugabyteDB Anywhere displays LDAP bind passwords configured …2.4
- CVE-2026-19662An attacker may be able to cause a `named` resolver to abort…5.9
- CVE-2026-19666On a resolver configured to use ``dns64``, if an applicable …7.5
- CVE-2026-19667If an attacker-controlled authoritative server can produce a…7.5
- CVE-2026-19668A BIND recursive resolver may experience excessive resource …5.3
Are you affected by CVE-2026-19656?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
