← back
CVE-2026-9645criticalCWE-78

ScadaBR Authenticated Remote Code Execution

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.9epss 0.3%
from disclosure to weapon73 days
Published on NVDMay 28
1st PoC+73d
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
ScadaBR · ScadaBR
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.