Skip to content
TenableCVE-2026-19656

Tenable ScadaLTS: code execution

Critical9.9CVE-2026-19656 · Published Aug 12, 2026 · updated Aug 25, 2026

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS server process (root), leading to full compromise of the underlying system.

Tenable advisory

Affected versions

PackageAffectedFixed in
ScadaLTS
Product
<= 2.7.8.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Tenable advisories

All Tenable
Advisory
Tenable Security Center: cross-site request forgery
Medium6.0Aug 14
Tenable Security Center: privilege escalation
High8.5Aug 14
Tenable Security Center: command injection
High8.6Aug 14
Tenable Security Center: remote code execution
Critical9.4Aug 14
Tenable ScadaLTS: cross-site scripting
Medium6.1Aug 12
Tenable Snipe-IT: insecure direct object reference
Medium5.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.