TenableCVE-2026-19657
Tenable ScadaLTS: cross-site scripting
Medium6.1CVE-2026-19657 · Published Aug 12, 2026 · updated Aug 25, 2026
ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ScadaLTS Product | <= 2.7.8.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-79
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 14 | Tenable Security Center: cross-site request forgery | Medium6.0 | 6.9.0 |
| Aug 14 | Tenable Security Center: privilege escalation | High8.5 | 6.9.0 |
| Aug 14 | Tenable Security Center: command injection | High8.6 | 6.9.0 |
| Aug 14 | Tenable Security Center: remote code execution | Critical9.4 | 6.9.0 |
| Aug 12 | Tenable ScadaLTS: code execution | Critical9.9 | No fix yet |
| Aug 11 | Tenable Snipe-IT: insecure direct object reference | Medium5.3 | 8.6.0 |