← Back to search

CVE-2026-84860

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-18

AI risk analysis

Summary
The flaw allows an authenticated user to bypass authorization and invoke any DWR method, leading to potential unauthorized access to restricted functionalities.
Exploitability
Exploitation is relatively easy for an authenticated user who can send a POST request with specific parameters to a permitted URL.
Blast radius
If exploited, this could lead to significant data breaches or system compromise, as any DWR method can be invoked regardless of URL-based access controls.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to ScadaLTS 2.8.1-release-candidate build 1 or later.
auth-bypasswebics

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body. This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-639

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.