TenableCVE-2026-19656
Tenable ScadaLTS: code execution
Critical9.9CVE-2026-19656 · Published Aug 12, 2026 · updated Aug 25, 2026
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ScadaLTS Product | <= 2.7.8.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 14 | Tenable Security Center: cross-site request forgery | Medium6.0 | 6.9.0 |
| Aug 14 | Tenable Security Center: privilege escalation | High8.5 | 6.9.0 |
| Aug 14 | Tenable Security Center: command injection | High8.6 | 6.9.0 |
| Aug 14 | Tenable Security Center: remote code execution | Critical9.4 | 6.9.0 |
| Aug 12 | Tenable ScadaLTS: cross-site scripting | Medium6.1 | No fix yet |
| Aug 11 | Tenable Snipe-IT: insecure direct object reference | Medium5.3 | 8.6.0 |