---
id: CVE-2026-94148
title: A vulnerability was determined in ScadaBR up to 1.1
summary: >-
  A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function
  EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the
  component Export Project Endpoint. This manipulation causes information
  disclosure. T…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-284
product: ScadaBR
affected:
  - ScadaBR 1.0
  - ScadaBR 1.1
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T20:17:41.100'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94148'
references:
  - url: 'https://github.com/ScadaBR/ScadaBR/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/ScadaBR/ScadaBR/commit/c852b4988a15bce6011ef169299ad604538f70a9
    label: cna@vuldb.com
  - url: 'https://github.com/ScadaBR/ScadaBR/releases/tag/v1.2'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94148'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894000'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408062'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408062/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894000'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00537
epssPercentile: 0.42762
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T19:27:13.953014Z'
ingestedAt: '2026-09-21T08:33:58.336Z'
---

## Overview

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.0 is recommended to address this issue. Patch name: c852b4988a15bce6011ef169299ad604538f70a9. The affected component should be upgraded. Import path was already gated with Permissions.ensureAdmin(); only export was left unprotected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
