Skip to content
TenableCVE-2026-19657

Tenable ScadaLTS: cross-site scripting

Medium6.1CVE-2026-19657 · Published Aug 12, 2026 · updated Aug 25, 2026

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.

Tenable advisory

Affected versions

PackageAffectedFixed in
ScadaLTS
Product
<= 2.7.8.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More Tenable advisories

All Tenable
Advisory
Tenable Security Center: cross-site request forgery
Medium6.0Aug 14
Tenable Security Center: privilege escalation
High8.5Aug 14
Tenable Security Center: command injection
High8.6Aug 14
Tenable Security Center: remote code execution
Critical9.4Aug 14
Tenable ScadaLTS: code execution
Critical9.9Aug 12
Tenable Snipe-IT: insecure direct object reference
Medium5.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.