Scadabr is an open-source SCADA and industrial control software platform whose vulnerability profile skews strongly toward critical-severity outcomes and has an elevated tendency toward confirmed in-the-wild exploitation. The recurring weakness classes—cross-site scripting, cross-site request forgery, OS command injection, missing authentication for critical functions, and session fixation—reflect the web-facing nature of the platform and underscore the exposure risk inherent to internet-accessible industrial control interfaces. Defenders should treat updates to this vendor as high-priority for any exposed deployments; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scadabr over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26828HIGH OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. | Jun 11, 2021 | 8.8 | 83 | YES | NO |
CVE-2021-26829MEDIUM OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | Jun 11, 2021 | 5.4 | 81 | YES | NO |
CVE-2026-8605CRITICAL In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin. | May 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-8603CRITICAL In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system. | May 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-8602CRITICAL In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and i | May 19, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-8604HIGH In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious we | May 19, 2026 | 8.8 | 35 | NO | NO |
CVE-2019-16344MEDIUM A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username | Oct 14, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-16321MEDIUM ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO. | Sep 15, 2019 | 6.1 | 21 | NO | NO |
CVE-2025-70973MEDIUM ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after | Mar 9, 2026 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scadabr.
Media articles that mention a CVE ID that affects a product developed by Scadabr — matched by CVE ID, not by vendor name.