Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-84860— Scada-LTS DWR Authorization Bypass - Systemic

Quick assessment

Affected
Scada-LTS Scada-LTS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ScadaLTS 2.8.1 发布候选版(build 0)存在一个授权绕过漏洞。 Spring Security 通过 URL 路径模式来控制 DWR 端点的访问权限,但 DWR 本身是根据 POST 请求体中的 和 参数来分发方法调用的。此外, 中的 设置被设为 ,从而禁用了 DWR 内置的来源(Origin)验证。 这意味着,任何已认证用户都可以通过向一个其有权访问的 URL(例如 )发送请求,并在 POST 请求体中指定受限的类名,从而调用任意 DWR 方法——即使该受限类在基于 URL 的访问控制下本应被限

CVSS 8.8 · High EPSS 0.48% · P39

Affected Version Matrix 1

VendorProduct Version RangeStatus
Scada-LTS Scada-LTS 2.8.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84860

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Scada-LTS DWR Authorization Bypass - Systemic
Source: CVE Program / CVE List V5
Vulnerability Description
ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body. This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Scada-LTS Scada-LTS 2.8.1 -

II. Public POCs for CVE-2026-84860

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84860

请登录查看更多情报信息。

Other References for CVE-2026-84860 (1)

Same Patch Batch · Scada-LTS · 2026-09-16 · 3 CVEs total

CVE-2026-84858 8.8 HIGH Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass
CVE-2026-84859 6.5 MEDIUM Scada-LTS Authenticated Blind SQL Injection

IV. Related Vulnerabilities

V. Comments for CVE-2026-84860

No comments yet


Leave a comment