CVE-2026-94148 | ScadaBR up to 1.1 Export Project Endpoint export_project.htm EmportDwr.createExportJSON information disclosure

SecurityVulns

A vulnerability has been found in ScadaBR up to 1.1 and classified as problematic. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure.

This vulnerability is handled as CVE-2026-94148. The attack can be initiated remotely. Additionally, an exploit exists.

The affected component should be upgraded.

Import path was already gated with Permissions.ensureAdmin(); only export was left unprotected.VulDB Recent EntriesRead More