What is CVE-2026-19656?
CVE-2026-19656: In ScadaLTS 2.7.8.1, a server-side method lacks authorization checks, allowing low-privileged authenticated users to execute arbitrary OS commands on the host. This leads to remote code execution (RCE), requiring immediate patching.
Azərbaycanca: CVE-2026-19656: ScadaLTS 2.7.8.1 platformasında server tərəfli metodun icazə yoxlaması olmaması səbəbindən, yalnız oxuma icazəli autentifikasiya olunmuş istənilən istifadəçi hostda ixtiyari OS əmrləri işlədə bilər. Bu, uzaqdan kod icrası (RCE) ilə nəticələnir, ona görə də dərhal təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What can an attacker achieve by exploiting CVE-2026-19656 in ScadaLTS 2.7.8.1?
Any authenticated user with read-only permissions can execute arbitrary OS commands on the host, leading to remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.