VYPR
Critical severity9.9NVD Advisory· Published May 28, 2026

CVE-2026-9645

CVE-2026-9645

Description

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated remote code execution in ScadaBR via exposed methods allows creating and executing arbitrary JavaScript as root, compromising the entire system.

Vulnerability

ScadaBR contains an authenticated remote code execution vulnerability (CVE-2026-9645) in its exposed methods that allow authenticated users to create and execute arbitrary JavaScript code on the server. The affected versions are all releases of the unmaintained ScadaBR project. No specific version numbers are provided in the available references, but the project is noted as unmaintained, implying all versions are vulnerable [1].

Exploitation

An attacker must have valid credentials to authenticate to the ScadaBR application. No special privileges beyond authentication are required. Once authenticated, the attacker can use the exposed methods to craft and submit arbitrary JavaScript code, which is then executed on the server [1].

Impact

The JavaScript executes with full root-level access, enabling complete system compromise. The attacker can achieve full compromise of confidentiality, integrity, and availability of the server. This includes the ability to execute arbitrary operating system commands as root, read, modify, or delete any data, and potentially pivot to other systems on the network [1]. The CVSS v3 score is 9.9 (Critical) with the vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) [1].

Mitigation

No fix is available. Tenable was unable to contact the project maintainers, and the project appears to be unmaintained [1]. Users are advised to restrict network access to the ScadaBR application to trusted users only, consider isolating the application, and if possible, migrate to an alternative actively maintained SCADA solution [1].

AI Insight generated on May 28, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.