VYPR
Medium severity4.8NVD Advisory· Published May 29, 2026· Updated May 29, 2026

CVE-2026-10057

CVE-2026-10057

Description

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ITS Intelligent SCADA System version 2.1 contains a stored XSS vulnerability allowing privileged remote attackers to inject persistent JavaScript executed on page load.

Vulnerability

ITS Intelligent SCADA System developed by ITP Technology, version 2.1 [1][2], contains a stored cross-site scripting (XSS) vulnerability (CVE-2026-10057). The flaw allows an attacker who has already obtained administrative privileges to inject persistent JavaScript code into a specific page, which is then executed in users' browsers whenever that page is loaded [1][2].

Exploitation

To exploit this vulnerability, an attacker must first have administrative access to the ITS Intelligent SCADA System [1][2]. With that privilege, the attacker can inject malicious JavaScript code into a vulnerable page that will be stored on the server. The injected script is automatically executed when any user (including other administrators or lower-privileged users) visits the affected page. No further user interaction beyond loading the page is required for the injected script to run [1][2].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session on the SCADA system [1][2]. The CVSS v3.1 vector is AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N, indicating low impact to confidentiality and integrity, and no impact to availability [1][2]. The attacker could potentially perform actions on behalf of the victim, steal session tokens, or deface the page, but the scope is changed meaning the injected script can impact resources beyond the vulnerable component, though with low confidentiality and integrity impact due to the necessary privileges and user interaction [1][2].

Mitigation

As of the publication date (2026-05-29), no patch or vendor fix has been disclosed in the available references [1][2]. Users of ITS Intelligent SCADA System version 2.1 should monitor ITP Technology for an update or security advisory. No workaround is described in the references. The CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.