CVE-2021-26828highunder attackCWE-434

CVE-2021-26828

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 39%
from disclosure to weapon0 days
Published on NVDJun 11
1st PoCMar 31
CISA KEV+1636d
exploitation probability
39%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
6 public exploit(s)
Action required by CISAfederal deadline: 2025-12-24

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

OpenPLC ScadaBR allows logged-in users to upload and run malicious JSP files on the server. This lets attackers take control of the system after gaining access to a user account.

Technical detail

Arbitrary file upload vulnerability in view_edit.shtm endpoint affecting OpenPLC ScadaBR (Linux ≤0.9.1, Windows ≤1.12.4). Authenticated users can upload JSP files that execute with server privileges, leading to remote code execution. Attack requires valid credentials but no additional exploitation steps.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.