CISA warns of critical ScadaBR vulnerabilities enabling remote code execution

Four vulnerabilities in ScadaBR 1.2.0 allow unauthenticated attackers to execute commands and inject arbitrary sensor data.

Illustration: CISA warns of critical ScadaBR vulnerabilities enabling remote code execution

Four vulnerabilities in ScadaBR 1.2.0 allow unauthenticated attackers to execute commands and inject arbitrary sensor data.

  • Four critical vulnerabilities discovered in ScadaBR 1.2.0 SCADA system
  • Attackers can execute commands as root without authentication
  • Affects critical infrastructure sectors including energy and water systems globally

CISA has issued an advisory warning of four critical vulnerabilities in ScadaBR version 1.2.0 that could allow unauthenticated remote code execution on SCADA systems. The vulnerabilities, designated CVE-2026-8602 through CVE-2026-8605, carry a maximum CVSS score of 9.1.

The most severe vulnerability, CVE-2026-8603, enables OS command injection that allows attackers to execute commands as root on the SCADA system. Another critical flaw, CVE-2026-8602, permits unauthenticated attackers to send HTTP GET requests to inject arbitrary sensor readings into the system.

The remaining vulnerabilities include cross-site request forgery (CSRF) issues and the use of hard-coded credentials, according to CISA’s advisory.

ScadaBR is deployed worldwide across critical infrastructure sectors including critical manufacturing, dams, chemical facilities, energy systems, and water and wastewater treatment plants. The Brazilian-headquartered company has not responded to CISA’s requests to collaborate on mitigating these vulnerabilities.

The vulnerabilities affect the missing authentication for critical functions, improper neutralisation of special elements in OS commands, and other security weaknesses that could compromise industrial control systems.

Why It Matters

These vulnerabilities present significant operational and regulatory risks for CISOs overseeing critical infrastructure. Unauthenticated remote code execution on SCADA systems could enable attackers to manipulate industrial processes, disrupt operations, or cause safety incidents. The vendor’s lack of response to CISA compounds the risk, as there is no clear remediation timeline for affected organisations.

What To Do Now

  • Inventory all ScadaBR installations to identify version 1.2.0 systems
  • Contact ScadaBR customer support through their GitHub repository for additional information as suggested by CISA
  • Implement network segmentation and access controls to limit exposure of affected SCADA systems
  • Monitor CISA’s advisory for updates on vendor responses and mitigation guidance

Sources