CVE-2026-8602
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
19/05/2026
Last modified:
19/05/2026
Description
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH



