CVE-2026-9645Disclosure(scadabr / scadabr)
LOWCVSS 9.9 · CRITICALSignal is active with 1 mentions in latest observed window
Immediate actions
- Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
0.0/ 10 priority
Sources & remediation
Vendor / third-party advisories
Weakness type (CWE)
CWE-78
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- scadabr
Threat summary
- 2 mentions across 2 observed days
- Momentum state: stable
What's happening
- Technical details provided in 2 signals
- Disclosure: 2 classified signals
- Peaked 1d ago at 1 mentions (2026-06-17); latest day: 1
- 2 total mentions across 2 days
Affected systems
Vendors
Products
scadabr
1 version affected across 1 product
Deep dive
Activity timeline2 mentions / 2d
Signal classification1 categories
Disclosure2100.0%
Referenced assets2 URLs
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | scadabr | scadabr | 1.2 | - | - |
