CVE-2021-26828

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 05, 2021
Published Date
June 11, 2021
Last Updated
December 04, 2025
Vendor
n/a
Product
n/a
Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
Tags
cisa

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

6.5

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 13:30:36 UTC) Source
Proof of Concept Available
Yes (added 2021-03-31 02:39:02 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:45:29 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

hev0x/CVE-2021-26828_ScadaBR_RCE

Type: github • Created: 2021-03-31 02:39:02 UTC • Stars: 3

Timeline

  • CVE ID Reserved

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • Added to KEVIntel