---
id: CVE-2026-84858
title: "ScadaLTS 2.8.1-release-candidate build 0 is affected by an\_Authenticated Remote Code Execution via Scripting Sandbox Bypass\n\n\n\nThe DWR \"DataSourceEditDwr\" class exposes the \"validateScript\" method that compiles and executes attacker-supp…"
summary: "ScadaLTS 2.8.1-release-candidate build 0 is affected by an\_Authenticated Remote Code Execution via Scripting Sandbox Bypass\n\n\n\nThe DWR \"DataSourceEditDwr\" class exposes the \"validateScript\" method that compiles and executes attacker-supp…"
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: Scada-LTS
product: Scada-LTS
affected:
  - Scada-LTS 2.8.1
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:18:42.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84858'
references:
  - url: 'https://www.tenable.com/security/research/tra-2026-60'
    label: vulnreport@tenable.com
tags:
  - nvd
  - cve.org
epss: 0.00838
epssPercentile: 0.56005
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T18:38:13.599510Z'
ingestedAt: '2026-09-16T14:57:28.030Z'
---

## Overview

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass



The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on this method and so it is possible for an attacker with access to a low privilege user to abuse this flaw by leveraging the DWR routing bypass.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
